If you discover a security issue affecting CalculatedPath, email hello@calculatedpath.com with a clear description of the issue, affected URLs or features, reproduction steps, and the potential impact.
What to Include
- A concise summary of the issue and why it matters.
- The exact page, API route, or workflow affected.
- Reproduction steps, proof of concept, or screenshots if they help.
- Any suggested remediation or mitigations, if you have them.
Please Avoid
- Accessing, modifying, or deleting data that does not belong to you.
- Running denial-of-service, brute-force, or other disruptive tests.
- Social engineering, phishing, or physical attacks against any person or provider.
Response
We review reports in good faith and aim to respond within a few business days. We do not currently operate a public bug bounty program.