Vulnerability Disclosure
At Crafty, the security of our platform, systems, and customer data is a top priority. We welcome responsible disclosure of security vulnerabilities that may affect our products or services.
If you believe you've identified a security vulnerability, please report it to vdp@craftydelivers.com with as much detail as possible, including:
- A description of the vulnerability
- Steps to reproduce the issue
- The affected URL, endpoint, or system
- The potential security impact
- Any supporting screenshots or proof of concept (if applicable)
Once we receive your report, we will:
- Acknowledge receipt as promptly as possible
- Validate and investigate the reported issue
- Prioritize remediation based on the severity and potential impact
- Keep you informed, when appropriate, throughout the remediation process
Guidelines
To help protect our customers and systems, we ask that you:
- Act in good faith.
- Avoid accessing, modifying, or deleting data that does not belong to you.
- Do not intentionally disrupt or degrade our services.
- Limit testing to only what is necessary to demonstrate the vulnerability.
- Give us a reasonable opportunity to investigate and remediate the issue before publicly disclosing it.
Out of Scope
The following activities are not considered part of this program and may result in legal action:
- Unauthorized access to customer data or confidential information
- Downloading, copying, or exfiltrating data
- Service disruption, denial-of-service attacks, or attempts to impair system availability
- Social engineering, phishing, or physical security attacks
- Extortion, including demands for payment in exchange for deleting or withholding data
Safe Harbor
If you conduct security research in good faith, follow the guidelines above, and promptly report any vulnerabilities you discover, Crafty will not pursue legal action related to your research.



