漏洞披露
如何报告安全问题。
Last updated:
范围
This policy covers security vulnerabilities in the Prism service at prismlens.net, including the web application, API, and any mobile clients we release. It does not cover third-party services (Supabase, Vercel, Anthropic, OpenAI, Stripe, Resend) — report issues in those directly to the vendor.
范围内
·Authentication and authorisation flaws (access control bypasses, session handling, privilege escalation).
·Data exposure or leakage (other users’ entries, embeddings, analysis, or personal data visible without authorisation).
·Injection flaws (SQL, template, command, prompt injection that leaks data across users).
·Remote code execution.
·Server-side request forgery (SSRF) or other infrastructure risks.
·Logic flaws that allow free access to paid features, bypass of rate limits, or financial loss.
·Supply-chain risks specific to Prism’s deployment.
范围外
·Third-party issues in Supabase, Vercel, Anthropic, OpenAI, Stripe, Resend — report to the vendor.
·Denial of service, volumetric attacks, or physical attacks.
·Social-engineering attacks against Prism staff.
·Self-XSS requiring the user to paste code into their own browser.
·Missing security headers with no demonstrable impact.
·Clickjacking on pages with no sensitive action.
·Issues requiring an already-compromised device or root/jailbreak.
·CSRF on endpoints with no security impact.
·Rate limiting / brute force without credential-valid impact.
·Reports generated entirely by automated scanners with no manual verification.
如何报告
电子邮件 security@prismlens.net 包含:
·A clear description of the issue.
·Steps to reproduce, or a proof-of-concept.
·Your assessment of impact (who is affected, how).
·Your contact details (optional) if you want attribution or a reply.
我们的承诺
·Acknowledge receipt within 3 business days.
·Triage and respond with our initial assessment within 7 business days.
·Keep you informed through remediation.
·Not take legal action against good-faith research conducted within this policy, provided you avoid accessing or exfiltrating other users’ data beyond the minimum needed to demonstrate the issue, do not degrade service availability, give us a reasonable window (default 90 days) before public disclosure, and comply with applicable law.
我们对您的要求
·Don’t test against real users’ data. Create a test account.
·Don’t use social engineering against Prism’s founders, staff, or users.
·Don’t exfiltrate data beyond what’s needed to prove the issue.
·Don’t publicly disclose before we’ve had a reasonable window to respond and remediate.
·Report in English or Arabic.
漏洞赏金
Prism 目前不运营现金赏金计划。对于重大问题,如果您同意,我们将公开承认、在更改日志条目中致谢您,并在可用的情况下发送 Prism 周边商品。我们的优先级是补救速度,而不是赏金预算 — 随着业务增长,我们将重新考虑。
安全港
在我们力所能及的最大范围内,您按照本政策进行的真诚研究:
·Is authorised by Prism and does not violate the Prism Terms of Service.
·Will not be grounds for civil or criminal action by Prism under applicable computer-misuse laws.
·Will not result in a complaint to your employer, regulator, or law enforcement.
这个安全港是我们的承诺,不保证第三方(支付处理商、基础设施提供商)会采取相同的立场。如有疑问,请在测试前咨询我们。
联系
·Security reports: security@prismlens.net
·General support: support@prismlens.net
·Privacy / DPO: privacy@prismlens.net · dpo@prismlens.net