Security

Responsible Disclosure

FixGrid welcomes reports from security researchers. This policy explains how to report a vulnerability and what you can expect from us.

How to report

Email us — we read every report.

[email protected]

Email [email protected] with:

A description of the issue and where you found it
The steps to reproduce it
The potential impact
Any supporting material (screenshots, request/response samples)
Our machine-readable contact is published at /.well-known/security.txt.
Safe harbor

Our commitment to you.

If you make a good-faith effort to comply with this policy during your research, FixGrid will:

Not pursue or support legal action against you for accidental, good-faith violations
Work with you to understand and resolve the issue promptly
Acknowledge your contribution if you wish (and with your permission)
What we ask of you

Test in good faith.

Give us a reasonable opportunity to fix the issue before any public disclosure
Do not access, modify, or delete data that isn't yours; use only test accounts/data you control
Do not degrade service (no denial-of-service / load testing)
Do not use social engineering, phishing, or physical attacks against FixGrid, our staff, customers, or sub-processors
Respect the privacy of residents and customers — stop and report if you encounter personal data
Scope

What's in and out of scope.

In scope

The FixGrid production web application (app.fixgrid.app) and the marketing site (www.fixgrid.app).

Out of scope

Our sub-processors' own infrastructure (Render, Cloudflare, Stripe, Resend, Anthropic — report those to the respective vendor), denial-of-service, spam/social-engineering, and findings that require a compromised device or physical access.

What to expect

How we respond.

Acknowledgement — within 2 business days
Triage & updates — we assess severity and keep you informed as we work toward a fix
Resolution — we remediate valid issues through our normal secure-development process and confirm closure with you
FixGrid does not currently run a paid bug-bounty program; we recognize good-faith research with our gratitude and, where appropriate, public acknowledgement.
Report a vulnerability

Found something? Tell us.

Contact [email protected]

See also our Sub-processor list and Security overview.