SUBMITPAK

Security

Security

SubmitPak is in early access. If you believe you've found a security vulnerability in the webapp, API, or generation engine, please report it to us privately rather than disclosing it publicly.

Reporting a vulnerability

Email josh@submitpak.com with a description of the vulnerability and its potential impact, steps to reproduce it (URL, request/response, a proof-of-concept — whatever you have), and any account/org context needed to reproduce it.

We're a small early-access team (currently a single-owner operation), so please be patient, but every report gets a reply and is tracked through to a fix. Expect an acknowledgment within 3 business days. There is no bug bounty program at this time.

Scope

In scope: the SubmitPak webapp and marketing site (submitpak.com), the generation API, and the document upload / package-generation pipeline. We're especially interested in:

  • Authentication or session handling issues
  • Cross-org data access — a project, upload, or generated package visible to an account it doesn't belong to
  • Share-link exposure (guessable or non-expiring tokens, access after revocation)
  • Anything that could leak, corrupt, or tamper with uploaded documents

Out of scope: denial-of-service / load testing against production, social engineering of SubmitPak staff or users, physical access attacks, and vulnerabilities in third-party services we use (report those to the vendor directly).

Responsible disclosure

Please give us a reasonable amount of time to fix an issue before disclosing it publicly, and limit testing to your own account/data — a proof of concept against a test account is enough; you don't need to access real user data to demonstrate a bug is real. We won't pursue legal action against good-faith security research that follows this policy.

Not a vulnerability report?

This page covers security vulnerabilities specifically. For questions about how we handle personal data, or to exercise a privacy right (access, correction, deletion, export), see the Privacy Policy instead — that's a separate process with its own contact form.

Report a vulnerability to josh@submitpak.com.

V.586