Constellation stores some of the most personal records people will ever create. Researchers who help us protect those records are partners, not adversaries.
Report a vulnerability| Target | Status | Notes |
|---|---|---|
| myconstellationplan.com (web app) | In scope | All authenticated routes. |
| API endpoints | In scope | REST and webhook endpoints. |
| Activation protocol logic | In scope | High priority — report immediately. |
| Trusted contact access flows | In scope | High priority — report immediately. |
| Third-party services (Clerk, Stripe, Plaid) | Out of scope | Report directly to the vendor. |
| Social engineering or phishing | Out of scope | Not a technical vulnerability. |
| Denial of service (DoS / DDoS) | Out of scope | Do not test this. |
| Physical security | Out of scope | — |
| Level | Description |
|---|---|
| Critical | Unauthorized access to another user's vault, documents, or activation materials. Authentication bypass. RCE. Mass data exposure. |
| High | Privilege escalation. Ability to trigger or manipulate another user's activation protocol. Broken access controls on PII endpoints. Significant data leakage. |
| Medium | CSRF on authenticated actions. Stored or reflected XSS. Insecure direct object references. Sensitive data in logs or error messages. |
| Low | Missing security headers. Non-sensitive information disclosure. Low-impact UI redress. Best-practice deviations without direct exploitability. |
"Good faith" means you tested only accounts you own, didn't access other users' data, didn't disrupt availability, and gave us reasonable time before publishing. Monetary bounties are not currently offered.
Machine-readable policy at /.well-known/security.txt per RFC 9116.