Skip to content
← Torna a Prism

Divulgazione delle vulnerabilità

Come segnalare un problema di sicurezza.

Ultimo aggiornamento:

Ambito di applicazione

This policy covers security vulnerabilities in the Prism service at prismlens.net, including the web application, API, and any mobile clients we release. It does not cover third-party services (Supabase, Vercel, Anthropic, OpenAI, Stripe, Resend) — report issues in those directly to the vendor.

Nel campo di applicazione

  • ·Authentication and authorisation flaws (access control bypasses, session handling, privilege escalation).
  • ·Data exposure or leakage (other users’ entries, embeddings, analysis, or personal data visible without authorisation).
  • ·Injection flaws (SQL, template, command, prompt injection that leaks data across users).
  • ·Remote code execution.
  • ·Server-side request forgery (SSRF) or other infrastructure risks.
  • ·Logic flaws that allow free access to paid features, bypass of rate limits, or financial loss.
  • ·Supply-chain risks specific to Prism’s deployment.

Fuori dall'ambito di applicazione

  • ·Third-party issues in Supabase, Vercel, Anthropic, OpenAI, Stripe, Resend — report to the vendor.
  • ·Denial of service, volumetric attacks, or physical attacks.
  • ·Social-engineering attacks against Prism staff.
  • ·Self-XSS requiring the user to paste code into their own browser.
  • ·Missing security headers with no demonstrable impact.
  • ·Clickjacking on pages with no sensitive action.
  • ·Issues requiring an already-compromised device or root/jailbreak.
  • ·CSRF on endpoints with no security impact.
  • ·Rate limiting / brute force without credential-valid impact.
  • ·Reports generated entirely by automated scanners with no manual verification.

Come segnalare

Email security@prismlens.net con:

  • ·A clear description of the issue.
  • ·Steps to reproduce, or a proof-of-concept.
  • ·Your assessment of impact (who is affected, how).
  • ·Your contact details (optional) if you want attribution or a reply.

Cosa ci impegniamo a fare

  • ·Acknowledge receipt within 3 business days.
  • ·Triage and respond with our initial assessment within 7 business days.
  • ·Keep you informed through remediation.
  • ·Not take legal action against good-faith research conducted within this policy, provided you avoid accessing or exfiltrating other users’ data beyond the minimum needed to demonstrate the issue, do not degrade service availability, give us a reasonable window (default 90 days) before public disclosure, and comply with applicable law.

Cosa ti chiediamo

  • ·Don’t test against real users’ data. Create a test account.
  • ·Don’t use social engineering against Prism’s founders, staff, or users.
  • ·Don’t exfiltrate data beyond what’s needed to prove the issue.
  • ·Don’t publicly disclose before we’ve had a reasonable window to respond and remediate.
  • ·Report in English or Arabic.

Bounty sui bug

Prism non gestisce attualmente un programma di bounty in denaro. Per i problemi significativi, ti riconosceremo pubblicamente (con tua autorizzazione), ti daremo credito in una voce di changelog e emetteremo merchandise Prism se disponibile. La nostra priorità è la velocità di correzione, non un budget di bounty — rivedremo man mano che cresceremo.

Porto sicuro

Nella massima misura in cui possiamo offrirti, la tua ricerca in buona fede secondo questa politica:

  • ·Is authorised by Prism and does not violate the Prism Terms of Service.
  • ·Will not be grounds for civil or criminal action by Prism under applicable computer-misuse laws.
  • ·Will not result in a complaint to your employer, regulator, or law enforcement.

Questo porto sicuro è il nostro impegno e non garantisce che terze parti (processori di pagamento, fornitori di infrastrutture) avranno la stessa visione. In caso di dubbi, chiedici prima di testare.

Contatti

Documenti correlati: Informativa sulla Privacy · Condizioni di Servizio.