Our approach
Lynkify handles fan data for independent artists and podcasters, so security reports are reviewed quickly and taken seriously. If you've found a vulnerability, we'd rather hear about it from you first.
Scope
The following are in scope for reports:
- lynkify.in and www.lynkify.in
- app.lynkify.in (the authenticated dashboard)
- Public creator pages on *.lynkify.in subdomains
- Custom domains pointed at Lynkify-hosted pages
- Public API endpoints under lynkify.in and app.lynkify.in
Out of scope
- Denial of service (DoS/DDoS) testing
- Social engineering of Lynkify staff, creators, or fans
- Physical security of offices or infrastructure
- Spam or content moderation issues (report these to [email protected] instead)
- Vulnerabilities in third-party services Lynkify integrates with but doesn't operate
- Missing security headers or best-practice suggestions with no demonstrated impact
Guidelines
When testing, please:
- Only test against accounts and data you own or have explicit permission to use
- Never access, modify, or delete another user's data
- Avoid automated scanning that could degrade service for other creators
- Give us a reasonable window to fix an issue before disclosing it publicly
- Don't demand payment as a condition of disclosure
How to report
Email [email protected] with:
- A clear description of the vulnerability and its potential impact
- Step-by-step instructions to reproduce it
- Affected URLs, endpoints, or account types
- Any proof-of-concept code, screenshots, or logs that help us verify it
What happens next
Security reports get priority review, typically starting the same day. We'll acknowledge your report, confirm the issue, and let you know once a fix has shipped. We may follow up with questions to help us reproduce or scope the issue.
Safe harbor
Good-faith security research conducted within these guidelines will not result in legal action from Lynkify. If a third party initiates action related to research performed under this policy, we will make it known that the research was authorized.