Authorized security research

Tefily bug bounty

We want researchers to try to break Tefily. This page is prior written authorization to find security vulnerabilities on systems we operate, using whatever technical methods you need.

What you may do

If the goal is finding a security vulnerability on in-scope Tefily systems, you may use any technical technique you believe is useful. That includes, without limitation:

  • Automated scanning, fuzzing, and brute-force of our own endpoints
  • Authentication, authorization, and tenancy bypass attempts
  • Injection, SSRF, path traversal, deserialization, and similar tests
  • Creating accounts, projects, orgs, apps, and other resources for testing
  • Exercising APIs, git hosting, file storage, hosting, DNS, and console flows
  • Chaining issues and demonstrating impact on systems we operate

In-scope systems

This authorization covers infrastructure and products operated by Tefily, including:

  • tefily.com and www.tefily.com
  • app.tefily.com (console)
  • api.tefily.com (platform and project APIs)
  • git.tefily.com and HTTPS git at api.tefily.com/git
  • files, registry, and related Tefily platform hosts
  • Tenant apps and domains served by Tefily hosting (including *.apps.tefily.com)

Third-party services we do not operate (payment processors, email providers, public cloud control planes we do not own) are out of scope.

How to report

Send findings to hello@kataflax.dev with enough detail for us to reproduce the issue.

Include

Affected URL or API path, the account or project used, steps to reproduce, and a short note on impact.

Proof

Screenshots, request/response excerpts, or a minimal proof of concept are welcome. Do not attach unrelated customer data.

Data handling

If you encounter another user’s data, stop at demonstration, keep only what is needed for the report, and do not share it publicly.

Rewards

We currently run this as an open research program. We will acknowledge valid reports and may offer a reward at our discretion.

Limits

Almost everything technical is allowed on in-scope systems. Please stay within these bounds:

Our systems only

Do not attack networks, accounts, or products that Tefily does not operate.

No physical or social attacks

This policy does not authorize physical intrusion, theft of hardware, or social engineering of Tefily staff or customers.

Do not ransom or extort

Do not demand payment as a condition of disclosing a vulnerability, and do not use findings to threaten Tefily or its users.

Minimize lasting harm

Prefer accounts and projects you create. Avoid destroying data you do not need to destroy to prove the issue.

FAQ

Yes. You may scan, fuzz, and otherwise stress in-scope Tefily systems if your purpose is discovering vulnerabilities.

No. This page is the authorization. Start testing, then email hello@kataflax.dev when you have something to report.

Stop further access to data that is not yours, include what happened in your report, and do not retain or publish that data. Accidental impact during good-faith research is covered by this policy.

Found something?

Email a report with reproduction steps. We read every submission.

Report a vulnerability