We want to know what we missed.
If you discover a security issue in WhiskerMatch, we encourage you to report it responsibly. We will take it seriously, investigate promptly, and keep you informed.
A real, database-backed application — not a static site.
WhiskerMatch is one Next.js application: public marketing pages, public forms that persist to a Postgres database (the Discovery Questionnaire and the pilot-request form — see Privacy), and an authenticated shelter/rescue application with real accounts, sessions, and organization-scoped data. It has server-side API routes, session-cookie authentication, and private file storage. The most relevant areas for research are authentication and session handling, organization-isolation boundaries, the public form endpoints, uploaded-file access controls, secure headers, and content security policy.
In scope
whiskermatch.com and its subdomains: the public site and its forms, sign-in and session handling, the authenticated shelter/rescue application, file upload and download endpoints, and API routes. Secure header configuration, content security policy, authentication and authorization, organization-isolation boundaries, and any unexpected data exposure.
Out of scope
Third-party services (Vercel, Supabase, email delivery) unless the vulnerability is specific to our configuration of those services. Do not attempt to access another organization's data as part of testing — report the boundary you found instead of crossing it.
Do not harm
Do not access, modify, or attempt to exfiltrate data that does not belong to you, including another organization's records. Do not disrupt site or application availability.
Report promptly
Send findings to cazar-brandes@outlook.com with a clear description, steps to reproduce, and the potential impact. We aim to acknowledge within 5 business days.
Responsible research is welcome here.
We will not take legal action against security researchers who report vulnerabilities in good faith and follow the guidelines above.
Acknowledgment within 5 business days
We will confirm receipt of your report and let you know if we need more information.
Investigation and fix
We will investigate the issue and work on a fix. We will keep you updated on our progress.
Keep it confidential
Give us reasonable time to investigate and fix before disclosing publicly. We will tell you when it is safe to disclose.
Credit if you want it
If you would like public credit for a discovery, we are happy to acknowledge your name on this page after the fix is deployed.
Found something? Let us know.
Email cazar-brandes@outlook.com with a clear description, steps to reproduce, and the potential impact. We will respond within 5 business days.
