Shepi field guide

    Responsible Disclosure

    If you've found a security issue in Shepi, we want to hear about it. This page explains what's in scope, how to report, and the commitments we make to researchers who report responsibly.

    Scope

    In scope

    shepi.ai and all subdomains, the Shepi web application, edge functions exposed under our Supabase project, and the accounting integration flow.

    Out of scope

    Findings against third-party services (Supabase, Stripe, Vercel), social engineering of Shepi staff or customers, physical attacks, denial-of-service testing, and automated scanner output without a working proof-of-concept.

    Not a vulnerability

    Missing security headers without a demonstrated impact, rate-limit observations, version disclosure, missing CSP on marketing pages, and self-XSS in your own session.

    Already known

    Issues already disclosed publicly or already fixed in a deployed release are out of scope for recognition.

    How to Report

    Email hello@shepi.ai with:

    • A description of the issue and its impact.
    • Steps to reproduce, ideally with a short proof of concept.
    • Any logs, screenshots, or video showing the issue.
    • The account or test environment you used (please don't test against other customers' data).

    A PGP key is available on request. Please do not file vulnerability reports through our support form, GitHub issues, or public social channels.

    Safe Harbor

    We won't pursue legal action against researchers who, in good faith, follow this policy. Specifically, we will not initiate or support claims under the CFAA, DMCA, or equivalent laws for research that:

    • Sticks to accounts and data you own, or test accounts you've created.
    • Avoids degrading service availability for other customers.
    • Does not exfiltrate or retain customer data beyond the minimum needed to demonstrate the issue.
    • Gives us a reasonable window to remediate before any public disclosure (we suggest 90 days; we'll talk if more time is needed).

    If a third party brings a claim against you for activity that complied with this policy, we'll make our position public.

    What to Expect

    01

    Acknowledgement within 3 business days

    We confirm receipt and assign an internal owner.

    02

    Status update within 10 business days

    Triage outcome: confirmed / not reproducible / out of scope, with reasoning.

    03

    Fix and disclosure timeline

    We share a target remediation window. Critical issues are usually patched within 7 days; lower-severity items roll into the next scheduled release.

    04

    Public disclosure

    Coordinated with you. We default to a brief writeup once the fix is deployed, crediting you if you'd like.

    Recognition

    We don't run a paid bug bounty today. We do publicly credit researchers (with your permission) on a hall-of-fame section we'll publish once we have entries to list. If your finding is material, we'll also send a small thank-you of our choice — said honestly, this is not a structured payout program.

    Questions about this policy: hello@shepi.ai. For everything else security-related, start at the Trust Center.

    Continue with Shepi

    Ready to Accelerate Your QoE Analysis?

    From raw financials to a structured, traceable diligence package.