schedule Last updated: August 2026

Security Disclosure

If you find a real issue in VibeCuff, we want to hear about it early and fix it fast.

How to report

Email security@vibecuff.com if you find a vulnerability in vibecuff.com.

We take security seriously, especially because this product exists to help other founders avoid blind spots.

What is in scope

The main site at vibecuff.com, the browser-based schema checker, and the waitlist form backend are in scope.

Anything outside those systems is not part of this disclosure process.

What is out of scope

We do not consider social engineering or physical attacks to be in scope.

Third-party services are also out of scope unless the issue is clearly inside something we control.

What to expect from us

We will acknowledge reports within 48 hours.

For critical issues, we aim to fix them within 14 days.

We ask for 90 days of coordinated disclosure before public posting. There is no bug bounty yet, but we will credit researchers by name if they want that.