Drawoble · Vulnerability Disclosure
Security Policy
We welcome reports from security researchers. This page explains what is in scope, how to report a vulnerability, what to expect from us, and the safe-harbor terms that protect good-faith research.
1. How to report
Send vulnerability reports to security@drawoble.com. Please do not report security issues through public channels, social media, or the general support address.
A useful report includes:
- a clear description of the issue and its security impact;
- step-by-step instructions to reproduce it;
- the affected URL, endpoint, or component;
- the date and time of your testing (with time zone);
- any account identifiers you used — please test only with your own account.
You do not need to prove exploitability beyond what is necessary to demonstrate the issue. A single screenshot or a short proof-of-concept is enough; do not extract, alter, or retain more data than that requires.
2. Scope
In scope
app.drawoble.com— the hosted application;drawoble.com— the public website;-
the Drawoble backend project on
*.supabase.co, but only where the finding is a misconfiguration on our side (for example a broken access-control rule on our data), not a vulnerability in the vendor's own platform.
Out of scope
- the underlying infrastructure of our vendors themselves — Cloudflare, Supabase, Hetzner, Resend, and Sentry — which should be reported to those vendors directly;
- social engineering of our staff, users, or vendors, and any physical attack;
- denial-of-service, volumetric, brute-force, or rate-limit stress testing;
- automated scanner output with no demonstrated, exploitable impact;
- missing "best-practice" hardening headers or configurations with no concrete exploit path;
-
reports that the Content-Security-Policy allows
'unsafe-eval'— this is a deliberate, documented requirement of our WebGL rendering engine, not an oversight; - vulnerabilities that require a already-compromised device, a rooted or jailbroken environment, or a physically present attacker.
3. What to expect from us
We are a small team and we take security seriously. When you report in good faith under this policy, we commit to:
- acknowledge your report within 72 hours;
- keep you informed as we investigate and work toward a fix on a best-effort basis;
- coordinate public disclosure with you, and ask that you hold public disclosure for up to 90 days to give us time to remediate.
4. Safe harbor
If you make a good-faith effort to comply with this policy during your research, we will consider your research authorised. We will not initiate or support legal action against you in connection with it, and we will not report it to law enforcement. If a third party brings a claim against you for activity that complied with this policy, we will make it known that your activity was authorised.
To stay within safe harbor, you must:
- access only data that belongs to your own test account, and stop as soon as you can demonstrate a vulnerability;
- never exfiltrate, alter, or destroy data beyond the minimum needed to prove the issue;
- never access, download, or retain another person's personal data;
- avoid any action that degrades, interrupts, or damages the service or the experience of other users;
- delete any data you retrieved during testing once your report is submitted, and on our request;
- give us a reasonable time to remediate before any public disclosure.
Activity that goes beyond good-faith research — extortion, data theft, service disruption, or accessing other users' data — is not authorised and is not protected by this policy.
5. Rewards
Drawoble does not currently operate a paid bug-bounty program. During private beta we recognise valid reports with credit in our security hall of fame, with your consent and under the name or handle you choose. We would rather be honest that there is no cash reward than have you spend time expecting one.
6. Other contacts
For security vulnerabilities, use security@drawoble.com. For content abuse, copyright takedown, or spam, use abuse@drawoble.com. Please do not use the general user-facing support addresses for security matters.
7. Governing terms
This policy is governed by the laws of the Republic of Türkiye. It is published in Türkçe and English; in case of any conflict between the two language versions, the Türkçe text prevails.