Security
Security
Effective date: July 12, 2026
SubmitPak is in early access. If you believe you've found a security vulnerability in the webapp, API, or generation engine, please report it to us privately rather than disclosing it publicly.
Reporting a vulnerability
Email josh@submitpak.com with a description of the vulnerability and its potential impact, steps to reproduce it (URL, request/response, a proof-of-concept — whatever you have), and any account/org context needed to reproduce it.
We're a small early-access team (currently a single-owner operation), so please be patient, but every report gets a reply and is tracked through to a fix. Expect an acknowledgment within 3 business days. There is no bug bounty program at this time.
Scope
In scope: the SubmitPak webapp and marketing site (submitpak.com), the generation API, and the document upload / package-generation pipeline. We're especially interested in:
- Authentication or session handling issues
- Cross-org data access — a project, upload, or generated package visible to an account it doesn't belong to
- Share-link exposure (guessable or non-expiring tokens, access after revocation)
- Anything that could leak, corrupt, or tamper with uploaded documents
Out of scope: denial-of-service / load testing against production, social engineering of SubmitPak staff or users, physical access attacks, and vulnerabilities in third-party services we use (report those to the vendor directly).
Responsible disclosure
Please give us a reasonable amount of time to fix an issue before disclosing it publicly, and limit testing to your own account/data — a proof of concept against a test account is enough; you don't need to access real user data to demonstrate a bug is real. We won't pursue legal action against good-faith security research that follows this policy.
Not a vulnerability report?
This page covers security vulnerabilities specifically. For questions about how we handle personal data, or to exercise a privacy right (access, correction, deletion, export), see the Privacy Policy instead — that's a separate process with its own contact form.
Report a vulnerability to josh@submitpak.com.