Security & vulnerability disclosure
We take the integrity of Sprig's food-fact data and the privacy of our contributors seriously. If you've found a security issue, we want to hear from you.
How to report
Email security@sprigmap.com with a description, steps to reproduce, and the impact. Please report privately. Don't open a public issue or post the details until we've had a chance to fix it.
Safe harbor
Good-faith research that respects user privacy, avoids data destruction, does not exfiltrate data beyond what's needed to demonstrate the issue, and does not degrade service for others will not be pursued. Give us reasonable time to remediate before any public disclosure and we'll credit you if you'd like.
In scope
- Access control / data access beyond your own account
- Injection, cross-site scripting, or request forgery
- Authentication or session handling flaws
- Manipulation of the vote / confidence trust layer at scale
- Exposure of private data (notes, saved places, contributor location)
Machine-readable contact: /.well-known/security.txt