Staging environment

Security

Found something. Tell us.

If you have found a vulnerability in sodalis.club, write us. We read every report and respond within five business days.

How to report

Email security@sodalis.club with a written description of the issue, the URL or endpoint involved, and any proof-of-concept that helps us reproduce it. We will acknowledge receipt within two business days and post a fix or written response within five.

Scope

In scope: sodalis.club, www.sodalis.club, any subdomain under sodalis.club, and any service Sodalis operates that handles member data.

Out of scope: third-party services we use (Vercel, Supabase, Stripe, Resend, Anthropic). Please report issues with those services to their respective security teams.

Safe harbor

We will not pursue legal action against researchers who act in good faith, who avoid accessing member data beyond what is necessary to demonstrate the issue, who do not exfiltrate or publicly disclose data, and who give us a reasonable window to fix the issue before publication.

What we ask

  • Do not run automated scans that overwhelm production.
  • Do not access another member's data without permission.
  • Do not publish details until we have shipped a fix.
  • Do let us thank you publicly if a fix lands.

Acknowledgments

We maintain a list of researchers who have helped us improve Sodalis. If you want to be named, tell us. If you want to stay anonymous, we keep your name out.

This page is the Policy URL referenced from /.well-known/security.txt per RFC 9116.