Our commitment
Spot.xyz Corporation, doing business as Specset ("Specset," "we," "us," or "our"), takes the security of the Specset platform and the project records our customers keep in it seriously. We value the work of security researchers and welcome reports of vulnerabilities in the services we operate.
This policy explains which systems you may test, how to send us a report, what we do once we receive one, and the safe-harbour terms that apply to research conducted in good faith and within these rules. It is the policy that our security.txt file (RFC 9116) points to.
We do not currently operate a paid bug bounty program. Reports are welcome and appreciated, but we do not offer monetary rewards.
1. Scope
This policy covers the internet-facing services Specset operates:
- www.specset.com and specset.com – the public marketing website, including this page and the FedRAMP public information at /fedramp.
- app.specset.com – the Specset web application, including its GraphQL, MCP and OAuth endpoints.
- api.specset.com – the Specset API.
Other Specset subdomains that we operate ourselves (for example, docs.specset.com) are also in scope. Services that a vendor hosts for us, such as the Trust Center, our status page and our e-mail and calendaring providers, are outside this policy: please follow that vendor's own disclosure program.
Any system not listed above, and any system belonging to a Specset customer, partner or supplier, is out of scope unless we agree otherwise with you in writing.
2. How to report
Send your report by e-mail to security@specset.com. The mailbox accepts mail from any sender and delivers to the founders who run Specset's security program. Reports that concern our FedRAMP obligations may also be sent to the FedRAMP Security Inbox, fedramp@specset.com. Both addresses are listed in /.well-known/security.txt.
A useful report includes:
- Where – the host, URL, endpoint or component affected.
- What – the type of issue (for example, an authorization bypass or an injection flaw) and its impact as you understand it.
- How – step-by-step instructions to reproduce the issue, with a proof of concept, request and response samples, or screenshots where they help. Please tell us which account or organization you used for testing.
- Who – how we can reach you for follow-up questions, and whether you would like to be credited if the issue is fixed.
Please keep the report to what is needed to demonstrate the issue. Do not include data belonging to other Specset customers; if you came across such data while testing, tell us that you did and describe it rather than attaching it.
3. What to expect from us
Once we receive a report we will:
- Acknowledge it with a human reply within two business days of receipt.
- Evaluate it within 14 days of receipt. We confirm whether the issue is reproducible, assess how reachable and exploitable it is, and assign a severity. Our assessed severity may differ from the one you propose, or from a scanner's rating, because it reflects our knowledge of the architecture and of real-world impact and exploitability.
- Remediate it against the targets in our vulnerability management procedure. Every confirmed finding carries a remediation target from its severity, measured from the day we detected it: Critical within 14 days, High within 30 days, Medium within 90 days and Low within 180 days. Findings that are reachable from the internet and likely to be exploited carry tighter targets, and we work to whichever is sooner.
- Keep you informed of our evaluation and, when the issue is fixed, let you know so that you can verify it.
Confirmed findings are tracked in the same register, and under the same timeframes, as findings from our own scanning and testing. The procedure that governs this is described on the Trust Center.
4. Rules of engagement
To keep our customers' projects safe while you test, we ask that you:
- Test only with accounts and organizations that you own or that we have created for you. Do not attempt to access, modify or delete data that belongs to another customer or user. If you find that a flaw exposes such data, stop, do not go further, and report it immediately.
- Do not perform denial-of-service or volumetric testing, and keep automated scanning to a rate that does not degrade the service for others.
- Do not use social engineering, phishing, or physical attacks against Specset staff, customers, suppliers or facilities.
- Do not exfiltrate more data than is needed to demonstrate the issue, do not retain data you did not create, and delete any data you obtained once the report is closed.
- Do not install persistence, pivot to other systems, or attempt to escalate an issue further once you have enough to demonstrate it.
- Do not test systems outside the scope in section 1, including third-party services we use.
- Do not use an issue you have found for any purpose other than reporting it to us.
The following are generally out of scope unless you can show a concrete security impact: missing security headers or best-practice settings with no demonstrated exploit, reports from automated tools without a working proof of concept, software version disclosure on its own, clickjacking on pages with no sensitive actions, and e-mail configuration (SPF, DKIM, DMARC) findings without a demonstrated spoofing path.
5. Safe harbour
When you conduct security research in good faith and in accordance with this policy, we consider that research to be authorized. In return we will:
- Not pursue or support civil legal action against you, and not refer you to law enforcement, for accidental or good-faith violations of this policy.
- Treat research carried out under this policy as authorized under applicable computer-misuse laws, including the Computer Fraud and Abuse Act, and not bring a claim against you for circumventing the technical measures we use to protect the in-scope services.
- Waive, for the limited purpose of research under this policy, any restriction in our Terms of Service that would otherwise prohibit that research.
- Make it known that your actions were conducted in compliance with this policy if a third party initiates legal action against you for research that complied with it.
This safe harbour applies to Specset only; it cannot authorize activity against third parties or exempt you from laws that apply to you. If you are unsure whether something you plan to do is covered, ask us at security@specset.com before you proceed.
6. Coordinated disclosure
We ask that you give us a reasonable opportunity to fix an issue before you talk about it publicly. Specifically:
- Please do not publish details of a vulnerability until we have told you it is remediated, or until 90 days have passed since you reported it, whichever comes first. If we need more time, for example because a fix depends on a supplier, we will ask and explain why.
- Please do not share the details with anyone else in the meantime, other than as required by law.
- Once the issue is fixed, we are happy to coordinate the timing and content of any public write-up with you, and to credit you publicly if you would like us to.
We will not share your report, your identity or your contact details outside Specset except where the law requires it, where it is needed to remediate the issue (for example, with a supplier whose product is affected) or where you have agreed to it.
7. Changes to this policy
We may update this policy from time to time. The current version is always published at this address and referenced from /.well-known/security.txt. Research conducted under an earlier version of the policy remains covered by the terms that were in force when it was carried out.
Questions about this policy can be sent to security@specset.com.