Responsible Disclosure
Found a vulnerability in UltraFlips? Report it responsibly at security@ultraflips.com. We aim to acknowledge good-faith reports within 48 hours.
Scope
In scope: app.ultraflips.com, authentication, account data isolation, public API abuse, Ultra AI spend abuse, card search scraping, and future marketplace/payment-adjacent surfaces.
Out of scope: denial-of-service testing without approval, social engineering, spam, physical attacks, attacks against third-party services, and data exfiltration beyond proof of impact.
Safe Harbor
We will not pursue action against researchers who act in good faith, avoid privacy harm, do not disrupt service, and give us reasonable time to fix before disclosure.
Rewards
Beta starts with public thanks and hall-of-fame credit. Cash bounty terms should be added after revenue and legal review.