Security Policy
Responsible Disclosure
URL2Pin is committed to maintaining the security of our platform and protecting our users' data. We welcome security researchers and the community to report any vulnerabilities they discover.
Reporting Security Issues
If you discover a security vulnerability, please report it to us at:
- Email: hello@url2pin.com
- Response Time: We aim to respond within 48 hours
- Disclosure: We will work with you to coordinate disclosure
What to Include
When reporting a vulnerability, please include:
- Description of the vulnerability
- Steps to reproduce the issue
- Potential impact assessment
- Suggested fix (if applicable)
- Your contact information
What We Do
- Acknowledge receipt of your report within 48 hours
- Investigate and validate the reported issue
- Work with you to understand the scope and impact
- Develop and test a fix
- Deploy the fix and verify resolution
- Coordinate public disclosure if appropriate
Scope
This policy applies to:
- url2pin.com and all subdomains
- Our API endpoints
- User data and privacy
- Authentication and authorization systems
Out of Scope
- Social engineering attacks
- Physical security testing
- Denial of service attacks
- Automated vulnerability scanning without permission
Recognition
We appreciate the security research community and will recognize responsible disclosures in our security acknowledgments (with your permission).
Safe Harbour
If you make a good-faith effort to follow this policy, we will not pursue or support legal action against you for your research. We consider such research authorised, and we will work with you to understand and resolve the issue quickly.
Good faith means: you stay within the scope above, you only access the minimum data needed to demonstrate the issue, you do not modify or delete anyone else's data, you do not degrade the service for other users, and you give us reasonable time to fix the issue before disclosing it publicly. If you are unsure whether something is in scope, ask us first athello@url2pin.com and we will tell you.
Rewards
URL2Pin is a small, independent product and we do not currently run a paid bug bounty. We will credit you by name in our acknowledgments if you would like, and we will always tell you what we changed as a result of your report.
Note: This security policy is subject to change. We will notify the community of any significant updates. Last updated: 17 September 2026.