Skip to main content
Vulnerability disclosure

We want to know what we missed.

If you discover a security issue in WhiskerMatch, we encourage you to report it responsibly. We will take it seriously, investigate promptly, and keep you informed.

Current scope

A real, database-backed application — not a static site.

WhiskerMatch is one Next.js application: public marketing pages, public forms that persist to a Postgres database (the Discovery Questionnaire and the pilot-request form — see Privacy), and an authenticated shelter/rescue application with real accounts, sessions, and organization-scoped data. It has server-side API routes, session-cookie authentication, and private file storage. The most relevant areas for research are authentication and session handling, organization-isolation boundaries, the public form endpoints, uploaded-file access controls, secure headers, and content security policy.

In scope

whiskermatch.com and its subdomains: the public site and its forms, sign-in and session handling, the authenticated shelter/rescue application, file upload and download endpoints, and API routes. Secure header configuration, content security policy, authentication and authorization, organization-isolation boundaries, and any unexpected data exposure.

Out of scope

Third-party services (Vercel, Supabase, email delivery) unless the vulnerability is specific to our configuration of those services. Do not attempt to access another organization's data as part of testing — report the boundary you found instead of crossing it.

Do not harm

Do not access, modify, or attempt to exfiltrate data that does not belong to you, including another organization's records. Do not disrupt site or application availability.

Report promptly

Send findings to cazar-brandes@outlook.com with a clear description, steps to reproduce, and the potential impact. We aim to acknowledge within 5 business days.

Safe harbor

Responsible research is welcome here.

We will not take legal action against security researchers who report vulnerabilities in good faith and follow the guidelines above.

Acknowledgment within 5 business days

We will confirm receipt of your report and let you know if we need more information.

Investigation and fix

We will investigate the issue and work on a fix. We will keep you updated on our progress.

Keep it confidential

Give us reasonable time to investigate and fix before disclosing publicly. We will tell you when it is safe to disclose.

Credit if you want it

If you would like public credit for a discovery, we are happy to acknowledge your name on this page after the fix is deployed.

Vulnerability disclosure

Found something? Let us know.

Email cazar-brandes@outlook.com with a clear description, steps to reproduce, and the potential impact. We will respond within 5 business days.