If you've found a security issue in Shepi, we want to hear about it. This page explains what's in scope, how to report, and the commitments we make to researchers who report responsibly.
Scope
In scope
shepi.ai and all subdomains, the Shepi web application, edge functions exposed under our Supabase project, and the accounting integration flow.
Out of scope
Findings against third-party services (Supabase, Stripe, Vercel), social engineering of Shepi staff or customers, physical attacks, denial-of-service testing, and automated scanner output without a working proof-of-concept.
Not a vulnerability
Missing security headers without a demonstrated impact, rate-limit observations, version disclosure, missing CSP on marketing pages, and self-XSS in your own session.
Already known
Issues already disclosed publicly or already fixed in a deployed release are out of scope for recognition.
How to Report
Email hello@shepi.ai with:
- A description of the issue and its impact.
- Steps to reproduce, ideally with a short proof of concept.
- Any logs, screenshots, or video showing the issue.
- The account or test environment you used (please don't test against other customers' data).
A PGP key is available on request. Please do not file vulnerability reports through our support form, GitHub issues, or public social channels.
Safe Harbor
We won't pursue legal action against researchers who, in good faith, follow this policy. Specifically, we will not initiate or support claims under the CFAA, DMCA, or equivalent laws for research that:
- Sticks to accounts and data you own, or test accounts you've created.
- Avoids degrading service availability for other customers.
- Does not exfiltrate or retain customer data beyond the minimum needed to demonstrate the issue.
- Gives us a reasonable window to remediate before any public disclosure (we suggest 90 days; we'll talk if more time is needed).
If a third party brings a claim against you for activity that complied with this policy, we'll make our position public.
What to Expect
Acknowledgement within 3 business days
We confirm receipt and assign an internal owner.
Status update within 10 business days
Triage outcome: confirmed / not reproducible / out of scope, with reasoning.
Fix and disclosure timeline
We share a target remediation window. Critical issues are usually patched within 7 days; lower-severity items roll into the next scheduled release.
Public disclosure
Coordinated with you. We default to a brief writeup once the fix is deployed, crediting you if you'd like.
Recognition
We don't run a paid bug bounty today. We do publicly credit researchers (with your permission) on a hall-of-fame section we'll publish once we have entries to list. If your finding is material, we'll also send a small thank-you of our choice — said honestly, this is not a structured payout program.
Questions about this policy: hello@shepi.ai. For everything else security-related, start at the Trust Center.