Vulnerability Disclosure Policy

GitVelocity is built and run by Headline. If you think you've found a security vulnerability in GitVelocity, we want to hear about it. This page sets out what you can test, how to test it, and how to report what you find.

Scope

In scope:

  • gitvelocity.dev, the web app and its public pages
  • api.gitvelocity.dev, the GitVelocity API
  • The MCP server at https://gitvelocity.dev/mcp

Out of scope:

  • The third-party services GitVelocity runs on or connects to, including GitHub, GitLab, Bitbucket, Auth0, Render, Neon and the AI providers (Anthropic, OpenAI, OpenRouter and Claude Platform on AWS). Report issues in those services to the vendor directly.
  • Customers' own repositories. The code in a repository connected to GitVelocity belongs to that customer, not to us.
  • Anything not listed above is out of scope, including Render preview environments and *.onrender.com hostnames.

Allowed testing

  • Test only against accounts and organizations you own, and create no more than two test accounts. Sign them up with a real email address you can be reached at (a +security alias is fine), not a disposable one, and include those addresses in your report.
  • Register no more than two OAuth clients, from your test accounts.
  • Never access, modify or delete another organization's data. If you can see data that belongs to another organization, stop testing and report it to us straight away.
  • Access only the minimum data needed to show the issue. Don't download, keep or share data that isn't yours, and delete anything you accessed once you've reported it. We may ask you to confirm you've deleted it.
  • Don't run automated vulnerability scanners, and don't attempt denial of service. Manual testing with your own tools is fine.
  • Don't register OAuth clients whose name, logo, client_uri or redirect domain imitates GitVelocity, Headline or any other company or product.
  • Don't spam or social-engineer GitVelocity users or Headline staff.
  • When you're done, delete your test accounts (Settings → Profile → Delete Account) and list the OAuth clients you registered in your report, so we can remove them.

Rewards

We don't currently run a formal bug bounty program. We evaluate every report we receive, and if we confirm that your finding is valid, we will get back to you about next steps.

Safe harbor

If you test GitVelocity in good faith and follow this policy, we won't take legal action against you for that testing. This doesn't cover third-party systems or conduct that breaks the law. If you're not sure whether something is allowed, ask us at support@headline.com before you test it.

How to report

Email support@headline.com. Put "Security" in the subject line, and include:

  • Steps to reproduce the issue
  • The affected URLs
  • The impact: what an attacker could do with it

We follow coordinated disclosure. Keep the details private until we've agreed a disclosure date with you. That date is after a fix is deployed and any affected customers have been notified, and no later than 90 days after your report unless we agree an extension.

Our commitment

  • We'll acknowledge your report within 5 business days.
  • We'll tell you whether we can reproduce the issue, and let you know when a fix is released.