We do not currently run a paid bug-bounty program. We do run a coordinated-disclosure program with acknowledgment, remediation, and a public hall-of-thanks. Real researchers are respected; low-effort scanner output is not.
How to report
Email privacy@ladle.chat with subject line “Security report — [short summary].” PGP encryption available on request via the same address (fingerprint published on /.well-known/security.txt).
What to include
- A clear description of the issue and its potential impact.
- Steps to reproduce — a proof of concept if the vulnerability isn't obvious from the description.
- The environment: URL, browser, OS, timestamp.
- Your name and how you'd like to be credited if we publish thanks (or specify anonymous).
Safe harbor
We will not pursue legal action against researchers who: (a) act in good faith, (b) do not access, modify, or destroy other users' data, (c) do not intentionally degrade the service, (d) give us reasonable time to remediate before public disclosure. If your research inadvertently breaches something, tell us — we assess intent, not the mistake.
In scope
- ladle.chat and all subdomains under our control.
- The iOS and macOS native apps.
- The public API (once shipped; see /api).
- Our downloadable assets (SVGs, PDFs, ZIPs) if you find one that ships malicious content.
Out of scope
- Third-party services LADLE integrates with (Anthropic, Stripe, Supabase, Vercel, Resend) — report to those vendors' own security teams.
- Denial-of-service or rate-limiting bypass demonstrations.
- Social engineering our staff.
- Physical attacks on our infrastructure (there isn't any).
- Reports generated by automated scanners with no manual analysis.
Response SLA
Hall of thanks
Researchers who report valid vulnerabilities are listed on this page (with their permission) alongside a brief summary of the class of issue and the date resolved. No researchers yet — the list will populate as reports arrive. We publish thanks not because it's PR, but because coordinated disclosure works better when credit is real.
SECURITY.TXT · /.well-known/security.txt