Security
Last Updated: August 25, 2026
We take the security of our customers' data seriously. If you believe you have found a vulnerability in Alfie, we want to hear about it.
Reporting a vulnerability
Email security@alfie.io. A useful report includes:
- The affected URL, endpoint, or component.
- Clear steps to reproduce the issue.
- What an attacker could actually do with it — the impact, not just the finding.
Machine-generated scanner output sent without any of the above is unlikely to receive a response.
We do not offer monetary rewards
Alfie does not operate a paid bug bounty program, and we do not pay for vulnerability reports. We are grateful for good-faith research and will credit you publicly if you would like us to, but no report — however severe — is eligible for payment, a gift, or any other compensation. Please do not send a report expecting one.
What you can expect from us
- We will acknowledge a good-faith report within 5 business days of receiving it.
- We will keep you updated as we investigate and work on a fix.
- We will credit you when the issue is resolved, if you want to be credited.
Ground rules
So that your research stays in good faith, please keep to the following:
- Test only against accounts and data you own. Create your own trial account rather than probing a live customer's.
- Do not access, modify, delete, or download data belonging to anyone else. If you encounter someone else's data, stop immediately and tell us what you saw.
- Do not run denial-of-service, load, or stress tests against our systems or our vendors'.
- Do not use social engineering, phishing, or physical attacks against our staff, customers, or vendors.
- Do not use an issue to send email, place content, or otherwise act as another user.
- Stop as soon as you have confirmed a vulnerability. Extract only the minimum needed to demonstrate it.
- Give us reasonable time to fix the issue before disclosing it publicly or to a third party.
Good faith
If you follow the ground rules above and report promptly, we will treat your research as authorised and will not pursue or support legal action against you for it. If a third party brings action against you for research that followed this policy, we will make it known that your activity was conducted in compliance with it.
This policy covers alfie.io and app.alfie.io. Our machine-readable contact details are published at /.well-known/security.txt in line with RFC 9116.
For anything that is not a security issue, please contact support@alfie.io instead.