Skip to content
UpdateTinus
security

Security

Our approach to security during pre-launch and how to report a vulnerability responsibly.

Last updated

UpdateTinus is not yet a running service. Today, updatetinus.com is a static website with no accounts, no login and no server-side database of visitors. That keeps the attack surface small, but we still take security seriously and want to build good habits before launch.

Our approach today

  • Minimal data: the site stores only theme preference, emoji reactions and form entries in your own browser's localStorage. We cannot read that data.
  • No form backend: forms open your email app via mailto links instead of posting data to our servers.
  • Limited third parties: we load Google Fonts and Tailwind CSS from content delivery networks, and we do not use analytics or ad trackers.
  • HTTPS: the site is intended to be served over encrypted connections.

Plans for launch

As we build the hosted product, we intend to design for least privilege, encrypt data in transit and at rest, keep dependencies updated, review code changes and isolate customer data. We will describe the real controls in place once the service exists. We do not hold any security certifications today and will not claim any until they are actually achieved.

Responsible disclosure

If you believe you have found a vulnerability in this website or anything related to UpdateTinus, please email [email protected]. Helpful reports include:

  1. a description of the issue and its potential impact;
  2. the affected URL or component;
  3. clear steps to reproduce, with screenshots or a proof of concept where helpful;
  4. how you would like to be credited, if at all.

Guidelines for researchers

  • Act in good faith and avoid privacy violations, data destruction or service disruption.
  • Do not use automated scanning that generates heavy traffic.
  • Do not use social engineering, phishing or physical attacks.
  • Give us reasonable time to investigate and fix before any public disclosure.

We will acknowledge reports as quickly as we can, keep you informed about progress and credit you if you wish. We do not currently run a paid bug bounty programme. We will not pursue action against researchers who follow these guidelines in good faith.

Please do not include sensitive personal data in your report unless it is essential to demonstrate the issue.

Want to try UpdateTinus first?

Early access is free while we build.

Join early accessarrow_forward