Reporting a security issue

Pushup RPG · the website, the apps and the service behind them

If you have found a way to see or change something you should not be able to, in the apps, on this website or in the service the apps talk to, we want to hear about it.

How to report

Email hello@pushup.quest with Security in the subject, and please do not open a public issue first. Put the details in the first email:

We reply to reports that include enough to reproduce the problem. A message that only says you have found something, without saying what, gives us nothing to act on.

While you are testing

No bug bounty

We do not run a bug bounty and we do not pay for reports. We will not sign an agreement or discuss terms before receiving a report: send the details, and we will read them.

What we do not treat as a vulnerability on its own

If you think one of these does matter in our case, show us how, and we will treat it like any other report.

The machine-readable version of this page is at /.well-known/security.txt. For anything that is not a security issue, the contact page has the right address.