Constellation. ← Back to site
Security · Responsible Disclosure

If you find something,
tell us first.

Constellation stores some of the most personal records people will ever create. Researchers who help us protect those records are partners, not adversaries.

Report a vulnerability
01 · Process

How coordinated disclosure works

01
Submit your report
Email security@myconstellationplan.com with detail. Use PGP if sensitive. Acknowledged within 2 business days.
02
We triage and confirm
Severity assessment and initial response within 5 business days.
03
We fix it
Critical/high patched within 14 days. Medium/low within 60 days. We'll notify you when deployed.
04
You publish, if you choose to
After the fix is live, you're free to publish. We ask you wait for our confirmation. We'll credit you by name or anonymously — your choice.
02 · Commitments

Response timing

2 /
Business days to acknowledge
5 /
Business days to triage
14 /
Calendar days to patch critical
03 · Scope

What we want to hear about

TargetStatusNotes
myconstellationplan.com (web app)In scopeAll authenticated routes.
API endpointsIn scopeREST and webhook endpoints.
Activation protocol logicIn scopeHigh priority — report immediately.
Trusted contact access flowsIn scopeHigh priority — report immediately.
Third-party services (Clerk, Stripe, Plaid)Out of scopeReport directly to the vendor.
Social engineering or phishingOut of scopeNot a technical vulnerability.
Denial of service (DoS / DDoS)Out of scopeDo not test this.
Physical securityOut of scope
04 · Severity

How we classify findings

LevelDescription
CriticalUnauthorized access to another user's vault, documents, or activation materials. Authentication bypass. RCE. Mass data exposure.
HighPrivilege escalation. Ability to trigger or manipulate another user's activation protocol. Broken access controls on PII endpoints. Significant data leakage.
MediumCSRF on authenticated actions. Stored or reflected XSS. Insecure direct object references. Sensitive data in logs or error messages.
LowMissing security headers. Non-sensitive information disclosure. Low-impact UI redress. Best-practice deviations without direct exploitability.
05 · Safe harbor

If you act in good faith, so will we.

  • We will not pursue legal action for good-faith research.
  • We will work with you to understand and validate findings.
  • We will notify you when the issue is resolved.
  • We will credit you publicly only if you'd like.

"Good faith" means you tested only accounts you own, didn't access other users' data, didn't disrupt availability, and gave us reasonable time before publishing. Monetary bounties are not currently offered.

06 · Contact

Where to send it

security@myconstellationplan.com
Monitored by the engineering team · Encrypted reports welcomed
PGP public key →

Machine-readable policy at /.well-known/security.txt per RFC 9116.

07 · Acknowledgments

Researchers we've worked with

No disclosures to date — we're in beta. Be the first.