Contact: mailto:security@shipcube.com Expires: 2027-06-06T00:00:00.000Z Preferred-Languages: en Canonical: https://clockie.ai/.well-known/security.txt Policy: https://clockie.ai/security Acknowledgments: https://clockie.ai/security#acknowledgements # Clockie security disclosure policy # We welcome responsible reports from security researchers. # # Scope: clockie.ai, www.clockie.ai, and (legacy) clockie.shipcubeai.com, # including the APIs and file storage backing those domains. Infrastructure # identifiers are omitted deliberately; we will confirm in-scope details with # researchers on request. # # Out of scope: rate-limit findings on auth endpoints, social-engineering, # physical attacks, third-party services we depend on (Firebase, Cloud Run), # clickjacking on pages with no sensitive actions, missing security headers # without demonstrated impact. # # Please do NOT: access data that doesn't belong to a test account you # control; run automated scanners against production; disrupt service for # other users; publicly disclose before we've had a chance to fix. # # Response targets: # - Acknowledgement within 48 hours # - Triage decision within 5 business days # - Patch ETA shared within 10 business days for valid issues