Vulnerability Disclosure

Last updated: March 1, 2026

Reporting a vulnerability

If you believe you've found a security vulnerability in Complinist, please report it directly to Cameron Stihel at cam@complinist.com. Use the subject line [SECURITY] followed by a brief description.

Please include:

  • Type of vulnerability (e.g., XSS, authentication bypass, injection)
  • Where it occurs (URL, API endpoint, or application component)
  • Steps to reproduce
  • Your assessment of impact
  • Proof of concept if available (screenshots, code snippets)

I'll acknowledge receipt within 2 business days and provide an initial assessment within 5.

Scope

This policy covers:

  • The Complinist application (Docker deployment)
  • The complinist.com website and API endpoints
  • Website account authentication (Clerk) and subscription billing (Stripe)

Out of scope:

  • Third-party services (Clerk, Stripe) — report those to the respective vendors
  • Social engineering or phishing attacks
  • Denial of service (DoS/DDoS)
  • Issues requiring physical access to a user's device
  • Missing security headers without demonstrated impact
  • Theoretical vulnerabilities without proof of exploitability

Responsible disclosure guidelines

Please:

  • Make a good-faith effort to avoid privacy violations, data destruction, and service disruption
  • Don't access, modify, or delete data that doesn't belong to you
  • Don't exploit a vulnerability beyond the minimum needed to demonstrate it
  • Give reasonable time to respond before any public disclosure
  • Don't use automated scanners that generate excessive traffic

Safe harbor

Security research conducted in good faith under this policy is considered:

  • Authorized under the Computer Fraud and Abuse Act (CFAA)
  • Exempt from DMCA anti-circumvention provisions
  • Exempt from restrictions in our Terms of Service that would interfere with security research

I will not pursue legal action or involve law enforcement against researchers acting in good faith under this policy.

Severity and response

Vulnerabilities are prioritized by severity. Target resolution times:

  • Critical (CVSS 9.0–10.0) — complete system compromise, large-scale data exposure. Target: 48 hours.
  • High (CVSS 7.0–8.9) — significant unauthorized access or privilege escalation. Target: 7 days.
  • Medium (CVSS 4.0–6.9) — moderate impact, may require specific conditions. Target: 30 days.
  • Low (CVSS 0.1–3.9) — minimal impact or significant prerequisites. Target: 90 days.

These are targets, not guarantees. I'll keep you updated on progress throughout the process.

Contact

Cameron Stihel
Email: cam@complinist.com
Location: Huntsville, Alabama, United States