Security

Last updated: 2026-07-20

This page describes how to report security issues for Moldable, including Accounts, Sync and Moldable Drive, the desktop app, official apps, skills, Moldable Artifacts, and any future billing features.

Contact

If you discover a security vulnerability, email:

Please include:

  • A clear description of the issue
  • Steps to reproduce
  • Affected versions/components
  • Affected Account, device, synced location, Artifact URL, publish key flow, API route, or file path, if relevant; do not include passwords, session tokens, recovery material, or other secrets
  • Any proof-of-concept details and potential impact

For copyright, privacy, or abusive-content reports about a published Artifact, email hello@moldable.sh unless the report also involves a security vulnerability.

Disclosure Policy

We request coordinated disclosure:

  1. Report the issue privately by email.
  2. Give us reasonable time to investigate and ship a fix.
  3. Avoid public disclosure until we confirm remediation or agree on a timeline.

Safe Testing Guidelines

When testing, please:

  • Avoid accessing, modifying, or deleting data that is not yours
  • Avoid service disruption (DoS, resource exhaustion, spam)
  • Use the minimum proof needed to demonstrate impact
  • Test Account and Sync behavior only with Accounts, devices, and data you own or have permission to use
  • Test Artifact publishing, update, unpublish, and public-read behavior only with Artifacts you own or have permission to test
  • Do not attempt to guess private credentials, exfiltrate secrets, access unpublished Artifacts, or enumerate unlisted Artifact URLs beyond what is necessary for a report

These guidelines do not authorize access to another person's data or any activity that would violate law or our Terms. We do not currently offer a paid bug-bounty program or promise payment for reports.

Response Expectations

We aim to:

  • Acknowledge reports promptly
  • Triage severity and impact
  • Share status updates during remediation
  • Credit reporters when appropriate (if requested)

Related Resources