Responsible disclosure

Help us keep TinyX secure.

TinyX is not a formal public bug bounty with fixed payouts. We still welcome good-faith reports — and we treat them with urgency, respect, and credit when you want it.

How to report

Email support@tinyx.co with a clear write-up. Prefer PGP? Use the key linked from security.txt.

Include in your report

  • A clear description of the vulnerability
  • Steps to reproduce (more detail means faster triage)
  • Potential impact as you understand it
  • Your contact information so we can follow up

What we promise

Straight talk from the people who ship the code.

Acknowledgement within 24 hours We confirm receipt and assign someone to your report.
Triage within 72 hours We assess severity, confirm the issue, and share a timeline.
No legal threats Follow this policy and we will not pursue legal action against you.
Credit (unless anonymous) We publicly thank researchers who want recognition — see below.
Direct human communication No ticket bots. You talk with the people who fix the code.

Scope (summary)

High-level only — the authoritative list lives on tinyx.co/security.

In scope

  • Auth / authorisation bypasses
  • XSS, injection, SSRF
  • Encryption implementation flaws
  • Data exposure or leakage
  • Privilege escalation across tiers or roles
  • Webhook / API abuse, session issues
  • Bypasses of link expiry, download limits, or access controls

Out of scope

  • Social engineering or phishing our team
  • DoS / DDoS testing on production
  • Issues in third-party services (report to them)
  • Missing headers without a demonstrable exploit
  • Self-XSS or physical-access requirements
  • Scanner output without a verified exploit

Full scope, testing rules, and stack details: https://tinyx.co/security

Rewards

There is no fixed bounty table. When we reward a finding, it is discretionary — cash, a lifetime Pro/Max account, a public shoutout, or a mix — depending on severity and impact.

What we can guarantee

If you find something real and report it responsibly, we will not ignore you, and we will not be cheap about recognising the work.

Rules of engagement

Researchers we thank

Public credit for people who reported issues in good faith. This wall grows as TinyX credits more researchers.

Huzaifa

Muhammad Huzefa

Asfahan

achilleus

Prefer to stay anonymous? Say so when you report — we will honour that.

Found something?

Email us. Clear description, repro steps, impact, and a way to reach you.