PulseRepo
FeaturesWho it's forHow it worksScan a repoPricingFAQContact us
Sign inStart free
← Back to PulseRepo

Security & vulnerability disclosure

We take reports seriously and read every one. Please read this page before sending one - it answers the two questions that come up most.

Reporting an issue

Email [email protected] with steps to reproduce, the affected URL or endpoint, and what an attacker actually gains. Please give us a reasonable window to fix the issue before disclosing it publicly, and don't access, modify, or retain data that isn't yours while testing.

No paid bounty program

PulseRepo does not operate a bug bounty program and does not pay rewards. We are a small independent product, and this is not a negotiating position - there is no budget line for it. We're glad to credit you by name in the fix notes if you'd like. Reports sent with an invoice, a payment demand, or a disclosure deadline attached will not receive a reply.

What's in scope

Anything that lets someone read or change data they shouldn't: authentication or session flaws, cross-tenant access to another account's repositories or reports, injection, remote code execution in the analysis worker, exposure of repository access credentials or API keys, or a way around the free-tier and rate limits that enables real abuse.

What's out of scope

We already know about, and are not looking for reports on, the following. These come almost entirely from automated scanners and we can't act on them:

  • Missing or "weak" security headers with no demonstrated exploit.
  • Clickjacking on pages with no state-changing one-click action.
  • SPF, DKIM, DMARC, or other email-configuration findings without a working spoofed message that passes our current policy.
  • Missing rate limits on endpoints that don't send email or cost us compute.
  • Self-XSS, or anything requiring the victim to paste code into a console.
  • Software version disclosure, banner grabbing, or output from a scanner pasted verbatim without analysis.
  • Reports about third-party services we use (our host, CDN, or email provider) - please send those to the provider.
  • Denial of service, volumetric testing, social engineering, or physical attacks. Please don't run these against us.

Good-faith testing

If you follow this policy, test only against your own accounts and data, and avoid degrading the service for others, we will treat your research as authorized and won't pursue action over it. See our Terms for the general rules of use.

PulseRepo

Process-health visibility for the people who care about a codebase - written as questions, never as a verdict on the people who build it.

Product

  • Features
  • How it works
  • Scan a public repo
  • Sample report
  • Pricing
  • Sign in

Who it's for

  • Tech leads
  • Founders
  • Investors

Company

  • FAQ
  • Blog
  • Contact
  • Privacy
  • Terms
© 2026 PulseRepo. All rights reserved.Built for clarity, not surveillance.