Security

Vulnerability Disclosure

We welcome responsible disclosure. If you believe you've found a security issue, we want to know about it.

Reporting a Vulnerability

If you believe you've found a security issue in Passed Plan, email security@passedplan.com with reproduction steps. We review all valid reports, respond promptly, and credit researchers who wish to be named.

A PGP key is available on request from the above address for encrypted communication.

Passed Plan does not currently offer monetary rewards or operate a bug bounty program.

Guidelines

  • 1Give us a reasonable time (at least 90 days) to investigate and remediate before public disclosure.
  • 2Avoid accessing, modifying, or deleting data that does not belong to you.
  • 3Do not perform testing that could disrupt availability for other users (no DoS, no automated high-volume scanning without prior written permission).
  • 4Provide a clear description with steps to reproduce, an impact assessment, and any proof of concept.

In scope

  • passedplan.com and all subdomains
  • The Passed Plan iOS and Android apps (when released)
  • The Passed Plan API (api.passedplan.com if applicable)

Out of scope

  • Social engineering attacks against Passed Plan employees or users
  • Physical attacks against our infrastructure
  • Denial of service (DoS/DDoS) attacks
  • Spam or phishing campaigns
  • Issues in third-party services we use (Supabase, Vercel, Stripe, etc.)
  • Vulnerabilities requiring physical device access
  • Issues already reported by another researcher

How it works

1

Email your report to security@passedplan.com with reproduction steps.

2

We acknowledge all reports within 2 business days.

3

We verify and reproduce the issue.

4

We remediate the vulnerability and keep you informed of progress.

5

We credit you in our security acknowledgments (optional — we respect anonymity).

Acknowledgments

The following researchers have responsibly disclosed security issues to Passed Plan:

No reports yet — be the first.

Found something?

Email security@passedplan.com

Subject line format: [SECURITY] Brief description