Security Research

Security Policy

We take security seriously. If you've found a vulnerability, we want to hear from you.

Last updated: January 26, 2026

At Invoist, we value the security community and welcome responsible disclosure of vulnerabilities. This policy outlines how to report security issues and what you can expect from us.

1 Responsible Disclosure

We encourage security researchers to responsibly disclose vulnerabilities to us before making them public. We commit to working with you to understand and address legitimate security issues promptly and transparently.

2 Scope

The following are in scope for security research:

  • The Invoist web application (invoist.app)
  • Authentication and authorization mechanisms
  • Data handling and storage
  • API endpoints
  • Payment and financial data handling

3 Out of Scope

The following activities are not permitted and are out of scope:

  • Denial of service (DoS/DDoS) attacks
  • Social engineering or phishing attacks against our employees or users
  • Physical attacks against our infrastructure
  • Accessing, modifying, or deleting data belonging to other users
  • Automated vulnerability scanning that generates excessive traffic
  • Spam or rate-limit testing
  • Third-party services we use (report to them directly)

4 How to Report

If you've discovered a security vulnerability, please email us with the following information:

  • A description of the vulnerability and its potential impact
  • Detailed steps to reproduce the issue
  • Any relevant screenshots, videos, or proof of concept
  • Your contact information for follow-up questions

5 What to Expect

When you submit a vulnerability report:

1
Acknowledgment

We will acknowledge receipt of your report within 3 business days.

2
Assessment

We will investigate and assess the vulnerability, keeping you informed of our progress.

3
Resolution

We will work to fix confirmed vulnerabilities as quickly as possible.

4
Recognition

With your permission, we will publicly acknowledge your contribution.

6 Safe Harbor

We will not pursue legal action against security researchers who:

  • Act in good faith and follow this policy
  • Avoid privacy violations (do not access other users' data)
  • Do not degrade or disrupt our services
  • Do not publicly disclose vulnerabilities before we've had reasonable time to address them

7 Bug Bounty Program

We do not currently offer a paid bug bounty program. However, we are happy to publicly acknowledge your contribution on this page if you report a valid vulnerability that we confirm and fix. Please let us know if you'd like to be credited.

Acknowledgments

We would like to thank the following security researchers for responsibly disclosing vulnerabilities:

No reports yet. Be the first to help us improve our security!