Security & Vulnerability Reporting

We take security seriously. If you find a vulnerability, please tell us privately.

Last updated: April 2025

How to report a vulnerability

If you discover a security vulnerability in TenderPath, please report it to us directly before disclosing it publicly. This gives us the opportunity to investigate and address the issue without exposing users to unnecessary risk.

Report to:

info@tenderpath.me

Subject line: Security Vulnerability Report

What to include in your report

  • A description of the vulnerability and the potential impact.
  • Steps to reproduce the issue or a proof-of-concept.
  • The affected URL, endpoint, or component.
  • Your contact details (optional, but helpful if we need to follow up).

What to expect from us

  • We will acknowledge your report within 5 business days.
  • We will investigate and aim to keep you informed of our progress.
  • We do not currently operate a formal bug bounty programme.

Service availability

TenderPath targets a monthly uptime of 99.5% for its core production service, measured per calendar month and excluding scheduled maintenance, emergency maintenance, force majeure events, and third-party service failures (Vercel, Neon, Stripe, Resend, Cloudflare). This commitment does not extend to support response or resolution timelines.

Responsible disclosure

We ask that you:

  • Do not access, modify, or exfiltrate user data beyond what is needed to demonstrate the vulnerability.
  • Do not perform denial-of-service attacks or disrupt service availability.
  • Give us reasonable time to investigate and respond before public disclosure.
  • Act in good faith throughout the process.

We commit to not pursuing legal action against researchers acting in good faith under these guidelines.

Scope

In scope: tenderpath.me, tenderpath.co, and associated API endpoints.

Out of scope: third-party services we use (Stripe, Vercel, Resend, Cloudflare). Please report vulnerabilities in those services directly to those providers.

Questions

For general security questions: info@tenderpath.me