Security

Reporting a vulnerability.

This page is the disclosure policy referenced by /.well-known/security.txt.

How to report

Email [email protected] with the subject line “Security”. Include the affected URL or app version, the steps to reproduce, and what an attacker could obtain. A short proof of concept helps; a full exploit chain is not required.

What to expect

  • An acknowledgement within five business days.
  • An assessment and a remediation plan, or an explanation of why the report is not treated as a vulnerability.
  • Credit in the release notes if you would like it.

Please do

  • Test only against accounts you own.
  • Report promptly and give us reasonable time to fix an issue before publishing.
  • Tell us right away if you access another person’s belief data by accident, and delete any copy of it.

Please do not

  • Run denial-of-service, load, or spam tests against the service.
  • Use social engineering, phishing, or physical attacks against people or infrastructure.
  • Read, change, or retain data belonging to anyone else.

Scope

The web application at isthisstilltrue.com, its API, and the Android and iOS apps published under com.isthisstilltrue.app. Findings in third-party services such as PayPal or Mixpanel should be reported to those providers.

No bounty

There is no paid bug-bounty programme. Reports are still welcome and are taken seriously.

Effective August 17, 2026