How to report
Email security@mydba.dev with a description of the issue, reproduction steps, and any supporting material. If you need encryption, request our PGP key in your first message and we will reply with it.
What to expect
- Acknowledgment within 2 business days of your initial report.
- Remediation plan within 7 days of acknowledgment for confirmed issues, including an expected fix window scaled to severity.
- Regular updates on fix progress.
- Public credit in release notes if you want it, once a fix is shipped.
Scope
In scope: the MyDBA web application (mydba.dev), the API (api.mydba.dev), the collector binary, and the database functions and row-level security policies that make up the backend.
Out of scope: social engineering of MyDBA staff, physical attacks, denial-of-service testing, and issues in third-party services (Clerk, Stripe, Vercel, Cloudflare) which should be reported to those vendors directly.
Safe harbor
We will not pursue legal action against researchers who act in good faith, follow this policy, avoid privacy violations and service disruption, and give us a reasonable window to fix issues before any public disclosure.