Vulnerability Disclosure Policy
If you have found a security issue in the chat2plan.com website or its waitlist, we want to hear about it, and we will not treat you as an adversary for telling us.
Version 1.0. Last updated: 1 October 2026
How to report
Email security@ilzaro.com. Machine-readable contact details are published at /.well-known/security.txt in accordance with RFC 9116.
Please do not report security issues through public channels, such as social media or a public issue tracker. Public disclosure before we have a fix puts other people at risk.
What to include
- The type of issue and the page or endpoint affected.
- Steps to reproduce it, ideally with the specific requests and payloads involved.
- What an attacker could actually do with it, in your assessment.
- Any proof-of-concept code, screenshots, or logs. Please redact any real personal data.
- How you would like to be credited, or that you would prefer not to be.
Reports in English are handled fastest. Write in whatever language you are comfortable in and we will manage.
What we commit to
| Stage | Our commitment |
|---|---|
| Acknowledgement | Within 7 business days of your report. |
| Initial assessment | Within 20 business days, including our severity view and whether we consider it in scope. |
| Progress updates | At least every 30 calendar days while the issue is open. |
| Resolution target | Critical and high severity issues come first. We will tell you our target date rather than leave you guessing. |
| Credit | Public acknowledgement on this page, if you want it. |
We are a very small team. These are real commitments and we intend to meet them, but we are not a company with a 24-hour security operations center. If something is actively being exploited, say so in your subject line and we will treat it accordingly.
Safe harbor
If you make a good-faith effort to comply with this policy during your research, we will:
- Consider your research authorized under the Computer Fraud and Abuse Act and comparable state computer crime laws, and we will not bring or support a claim against you under them.
- Not bring a claim against you under the anti-circumvention provisions of the Digital Millennium Copyright Act for circumventing technical measures in the course of your research.
- If a third party brings legal action against you for research conducted in good faith under this policy, make it known publicly that your actions were authorized.
This safe harbor is limited to claims that we control. We cannot waive claims held by our service providers or any other third party, and we cannot bind law enforcement. If your testing would touch a third party’s systems, get their authorization separately.
If you are unsure whether something is in scope, ask first. Email us before you test. We would much rather answer a question than argue afterward about whether a boundary was crossed. Asking in advance is itself evidence of good faith.
Scope
In scope
- The
chat2plan.comandwww.chat2plan.comwebsite, in English and in Spanish (the Spanish pages are under/es/). - The waitlist service: the endpoints under
/api/(/api/waitlist,/api/health) and the confirm and remove links in our waitlist emails (/confirmand/unsubscribe).
The Chat2Plan app is in development and not yet in scope.
Out of scope
- Systems operated by our providers rather than by us. Report those to the provider. Our providers are listed on our subprocessor page.
- Denial of service, volumetric, and resource exhaustion testing. Do not run these.
- Social engineering, phishing, or physical attacks against our team, the people on our waitlist, or our providers.
- Issues that require an already compromised device, browser, or email account.
- Reports generated solely by an automated scanner with no demonstrated impact.
- Missing security headers or TLS configuration findings with no demonstrated exploit path.
- Email configuration issues such as SPF, DKIM, or DMARC, unless you can demonstrate a working spoofing attack.
- Self-XSS, clickjacking on pages with no sensitive state-changing action, and version disclosure without a demonstrated vulnerability.
- Best-practice recommendations without an accompanying vulnerability. We welcome these, but they are not vulnerability reports.
Rules of engagement
- Only test with email addresses you own. Do not sign up, confirm, or remove anyone else’s address, and do not access, modify, or exfiltrate any other person’s data.
- Keep sign-ups to the few you need. Each one sends a real email, and the waitlist sends only a limited number of emails a day, so a flood delays other people’s confirmations.
- If you encounter real personal data, stop immediately. Do not save it, copy it, or share it. Tell us what you saw so we can assess the exposure, and delete your copy.
- Use the minimum access necessary to demonstrate the issue. Proving you can read one record is enough; do not enumerate the database.
- Do not degrade the service for other visitors.
- Give us reasonable time to fix it before disclosing publicly. Our default coordinated disclosure window is 90 days from your report. If we need longer we will explain why and agree a date with you rather than stall. If we fix it sooner, publish sooner.
- Do not demand payment in exchange for withholding a report. That is not security research.
Rewards
We do not currently operate a paid bug bounty. We are a pre-revenue company and we would rather say that plainly than run a program we cannot fund. What we do offer is a prompt, respectful response, public credit if you want it, and a commitment to fix what you find.
If that changes, this page will change with it.
Acknowledgements
Researchers who have reported valid issues and chosen to be credited are listed here.
No reports yet. This section will be populated as reports come in.
Reporting a privacy concern instead
If your concern is about how we handle data rather than a technical vulnerability, write to privacy@ilzaro.com. Our Privacy Policy describes your rights and how to exercise them.
Ilzaro LLC.