Security
Reporting a vulnerability.
This page is the disclosure policy referenced by /.well-known/security.txt.
How to report
Email [email protected] with the subject line “Security”. Include the affected URL or app version, the steps to reproduce, and what an attacker could obtain. A short proof of concept helps; a full exploit chain is not required.
What to expect
- An acknowledgement within five business days.
- An assessment and a remediation plan, or an explanation of why the report is not treated as a vulnerability.
- Credit in the release notes if you would like it.
Please do
- Test only against accounts you own.
- Report promptly and give us reasonable time to fix an issue before publishing.
- Tell us right away if you access another person’s belief data by accident, and delete any copy of it.
Please do not
- Run denial-of-service, load, or spam tests against the service.
- Use social engineering, phishing, or physical attacks against people or infrastructure.
- Read, change, or retain data belonging to anyone else.
Scope
The web application at isthisstilltrue.com, its API, and the Android and iOS apps published under com.isthisstilltrue.app. Findings in third-party services such as PayPal or Mixpanel should be reported to those providers.
No bounty
There is no paid bug-bounty programme. Reports are still welcome and are taken seriously.
Effective August 17, 2026