More to Roam

    Security & Responsible Disclosure

    RFC 9116 contact at /.well-known/security.txt


    Reporting a Vulnerability

    We appreciate the security research community and welcome reports of vulnerabilities affecting More to Roam. To report a suspected security issue, please email security@moretoroam.com.

    Please include in your report:

    • A clear description of the issue and its potential impact
    • Steps to reproduce, including any URLs, requests, or proof-of-concept code
    • Affected pages, endpoints, or components
    • Your name or handle if you would like to be credited (optional)

    We will acknowledge receipt within 3 business days and aim to provide an initial assessment within 10 business days.

    Scope

    The following targets are in scope:

    • moretoroam.com and its subdomains
    • Our public APIs and Supabase Edge Functions exposed by the application

    The following are out of scope:

    • Issues in third-party services we use (Stripe, Supabase, Vercel, Iubenda, Google services, Resend, etc.) — please report those directly to the vendor
    • Denial-of-service (DoS or DDoS) testing of any kind
    • Social engineering of our staff, contractors, partners, or users
    • Physical attacks or attacks against our offices
    • Spam, content-injection, or SEO-manipulation reports without a security impact
    • Automated-scanner output without a manually-verified, exploitable finding

    Safe Harbor

    We will not pursue legal action against researchers who:

    • Make a good-faith effort to comply with this policy
    • Avoid privacy violations, data destruction, or service disruption
    • Do not exploit a vulnerability beyond what is necessary to confirm it
    • Do not disclose the issue publicly before we have had a reasonable opportunity to address it
    • Do not access or modify data belonging to other users

    Coordinated Disclosure

    We ask that you give us at least 90 days from initial report to address the issue before public disclosure. We are happy to coordinate a disclosure timeline that works for both parties.

    Recognition

    We do not currently operate a paid bug-bounty programme. With your permission, we are glad to publicly thank researchers who responsibly report valid security issues.


    © 2026 Thane Digital LLC. All rights reserved.