Security Policy
Last updated: August 2026
Arte & Cera handles reproductive and mental health data. If you’ve found a security vulnerability — especially anything that could expose that kind of data — we want to hear about it before anyone else does, and we want to make it easy and safe for you to tell us.
Scope
In scope:
- arteandcera.com and all subdomains
- The Arte & Cera iOS and Android apps
- Our public API endpoints
Out of scope:
- Third-party services we integrate with but don’t control (Clerk, Neon, Resend, Anthropic, Vercel, Oura) — report those directly to the provider
- Social engineering, phishing, or physical attacks against staff
- Denial-of-service or load-testing without prior written permission
- Findings that require physical access to a user’s unlocked device
- Automated scanner output with no demonstrated, specific impact — a raw vulnerability scanner report isn’t itself a valid submission, show us what it means
How to report
Email security@arteandcera.com with:
- A description of the vulnerability and its potential impact
- Steps to reproduce (proof-of-concept code or a screen recording helps)
- The URL, endpoint, or app version affected
Please don’t:
- Access, modify, or delete data that isn’t yours, beyond what’s strictly needed to demonstrate the issue
- Publicly disclose the issue before we’ve had a chance to fix it — see “Coordinated disclosure” below
- Use a finding to pivot into further exploitation “just to see how far it goes” — stop at proof of concept
Our commitment to you
| Acknowledge your report | Within 3 business days |
| Initial triage | Within 7 business days |
| Status updates while open | At least every 14 days |
| Fix — Critical severity | Within 15 days of confirmation |
| Fix — High severity | Within 30 days |
| Fix — Medium severity | Within 60 days |
| Fix — Low / informational | Next regular release cycle |
Severity follows CVSS 3.1 as a starting point, adjusted for what the data actually is here — a finding that exposes assessment answers or cycle data gets treated as more severe than the score alone might suggest, given what this app stores.
Coordinated disclosure
We ask for 90 days from your report before any public disclosure, or until we’ve shipped a fix and confirmed it with you, whichever is sooner. If you need more time before disclosing, or we need more time to fix something complex, we’ll ask — this is a conversation, not a deadline either side springs on the other.
Safe harbor
We will not pursue legal action against you, or report you to law enforcement, for security research conducted in good faith and in accordance with this policy. This includes:
- Accessing or storing our data only to the extent necessary to demonstrate the vulnerability
- Making a good-faith effort to avoid privacy violations, data destruction, and service interruption
If a third party (e.g., a vendor named in “Scope” above) initiates legal action related to research covered by this policy, we will make it known that your research was authorized.
Recognition and rewards
Valid, in-scope reports are eligible for a reward, paid directly by us once a fix is confirmed:
| Severity | Reward |
|---|---|
| Critical | $500 – $1,500 |
| High | $200 – $500 |
| Medium | $50 – $200 |
| Low / informational | Public recognition (with your permission) |
The exact amount within each range depends on report quality — a clear write-up with a working proof of concept and a suggested fix earns more than a bare description of the same bug. We’ll also credit you publicly if you’d like, or keep you anonymous — your choice.
What happens to your report
Reports go to security@arteandcera.com, which is monitored directly (see security.txt). We don’t use an automated ticketing system for this yet — a human reads every report.