Vulnerability Disclosure

How to report a security issue to MyDBA and what to expect when you do.

How to report

Email security@mydba.dev with a description of the issue, reproduction steps, and any supporting material. If you need encryption, request our PGP key in your first message and we will reply with it.

What to expect

  • Acknowledgment within 2 business days of your initial report.
  • Remediation plan within 7 days of acknowledgment for confirmed issues, including an expected fix window scaled to severity.
  • Regular updates on fix progress.
  • Public credit in release notes if you want it, once a fix is shipped.

Scope

In scope: the MyDBA web application (mydba.dev), the API (api.mydba.dev), the collector binary, and the database functions and row-level security policies that make up the backend.

Out of scope: social engineering of MyDBA staff, physical attacks, denial-of-service testing, and issues in third-party services (Clerk, Stripe, Vercel, Cloudflare) which should be reported to those vendors directly.

Safe harbor

We will not pursue legal action against researchers who act in good faith, follow this policy, avoid privacy violations and service disruption, and give us a reasonable window to fix issues before any public disclosure.

Related