Reporting a Security Issue
Email [email protected] with SECURITY: at the start of the subject line. You’ll get a response within 24 hours.
Please don’t open a public issue or post details publicly before we’ve had a chance to fix it.
What helps
The more precisely you can describe what you did and what happened, the faster it gets fixed:
- What you were doing, and the URL or endpoint involved
- What you expected, and what actually happened
- Whether you could reproduce it, and how
- Anything you saw that you shouldn’t have — described, not attached
If you accessed data belonging to another account while testing, tell us. It changes what we have to do afterwards, and we’d much rather know.
What’s in scope
The GuestsKey web app and API, and the public repository. Issues in third-party services we integrate with — your lock manufacturer, your PMS, Stripe — should go to those providers, though we’re glad to help you route it.
What to expect
A human reply within 24 hours, usually much sooner. We’ll tell you whether we’ve reproduced it, and we’ll come back to you when it’s fixed.
We don’t run a paid bug bounty program. We’re a small team and we’d rather be honest about that up front than have you find out after the work.
Please avoid
Testing that degrades service for real customers — load testing, automated scanning against production, or anything that would open doors on properties you don’t own. If you need to test something that carries that risk, email first and we’ll work out a safe way.