SECURITY
Found something? Tell us. We’ll reply within 72 hours and we won’t threaten you.
🔐 Report a vulnerability
security@anything4clout.comA data exposure, or anything that looks wrong. You don’t need to prove it, exploit it, or write it up formally — a sentence and a screenshot is fine.
🤝 What we promise
We'll replyWithin 72 hours, from a person
We won't threaten youNo legal action for good-faith research reported privately
We'll tell you what happenedYou'll hear when it's fixed, not just when it's received
We'll credit youIf you want it. Anonymous is fine too
🎯 What counts
- ✓ Anything that exposes another person’s data
- ✓ Anything that lets someone act as another account
- ✓ Anything that awards points, prizes or positions incorrectly
- ✓ Anything that lets an adult reach a child, or bypasses an age check
- ✓ Anything that gets past moderation
- ✓ Authentication, session or permission flaws
The child-safety ones matter most. If you’ve found a way an adult could reach a minor here, or a way past moderation, say so in the subject line — we treat it as urgent.
🙏 What we’d ask
- · Don’t access anyone else’s data beyond what proves the issue exists
- · Don’t degrade the service — no load testing, no denial of service
- · Give us a reasonable window before publishing; we’ll tell you honestly how long we need
- · One report per issue is easier for both of us than a long thread
💛 We don’t pay bounties yet
We’re pre-launch and pre-revenue, so we can’t offer money. We can offer credit, a genuine thank-you, and a fast honest reply — and we’ll say so up front rather than waste your time. Out of scope: missing headers with no demonstrable impact, rate limits on public pages, raw automated-scanner output, and social engineering of our staff or users.
↪️ If it’s not a security issue
A child at risksafeguarding@anything4clout.comor 999 if it's immediate
Content that breaks the rulesreport@anything4clout.com
Your dataprivacy@anything4clout.com
Copyright or legallegal@anything4clout.com