Security
SodaPeach vulnerability disclosure policy · 1 September 2026
If you believe you have found a security vulnerability in SodaPeach, please report it privately so we can investigate and fix it.
How to report
Email security@sodapeach.com with a clear description, the affected URL or feature, steps to reproduce, and the potential impact. Please include only the minimum evidence needed to demonstrate the issue. Do not include passwords, tokens, private conversations, or other sensitive information.
Scope
This policy covers SodaPeach-owned websites, applications, and APIs operated on the sodapeach.com domain. Reports about Supabase, Cloudflare, Google, X, xAI, Stripe, or another provider's infrastructure should be sent to that provider instead.
Testing rules
When testing, use only your own account and data. Stop immediately if you encounter another person's data and tell us what happened without accessing, copying, or sharing it.
Please do not:
- Use social engineering, phishing, or impersonation.
- Perform denial-of-service, load, spam, or automated-account testing.
- Attempt destructive actions, data deletion, or persistence.
- Test third-party systems or services through SodaPeach.
- Publish or share a vulnerability before we have had a reasonable opportunity to respond.
What to expect
SodaPeach will acknowledge a report when practical, investigate its validity and impact, and communicate about remediation when we can. Please allow a reasonable period for us to assess and address a report. This policy does not create a bounty program, guarantee a reward, or provide a broad safe-harbor commitment.
Contact
Security reports: security@sodapeach.com
General support: support@sodapeach.com