Security

Last updated: 16 September 2026

Reporting. Found something? Email contact@feedrobin.com with what you found, where, and how to reproduce it. Plain email is fine; no form, no account, no encryption required. We read every report and answer within a few working days. The machine-readable version of this page is /.well-known/security.txt.

No paid bounty program. FeedRobin is a small, bootstrapped product and we don't pay for reports. We do fix confirmed issues quickly, tell you when the fix is live, and credit you here by name or handle if you'd like. Please tell us in your first message if you expect payment, so neither of us spends time on a misunderstanding.

In scope. Anything that lets someone read or change another user's catalog, feeds or account; anything that reaches our infrastructure; the free feed check being used to reach hosts it shouldn't; authentication or session weaknesses.

Not a finding on its own. Missing or “best practice” HTTP headers without a demonstrated impact, SPF/DMARC/DKIM configuration reports from automated scanners, clickjacking on pages with no state-changing actions, rate-limit observations without an exploit, version disclosure, and anything that requires a compromised device or physical access.

Please don't. Test against other people's stores or accounts, run denial-of-service or high-volume scans, or access data beyond what's needed to demonstrate the issue. Give us a reasonable time to fix before publishing.

What we protect. Product catalog data only; we never hold your customers' data. See the privacy policy for what is stored and where.