Vulnerability Disclosure Policy
GitVelocity is built and run by Headline. If you think you've found a security vulnerability in GitVelocity, we want to hear about it. This page sets out what you can test, how to test it, and how to report what you find.
Scope
In scope:
gitvelocity.dev, the web app and its public pagesapi.gitvelocity.dev, the GitVelocity API- The MCP server at
https://gitvelocity.dev/mcp
Out of scope:
- The third-party services GitVelocity runs on or connects to, including GitHub, GitLab, Bitbucket, Auth0, Render, Neon and the AI providers (Anthropic, OpenAI, OpenRouter and Claude Platform on AWS). Report issues in those services to the vendor directly.
- Customers' own repositories. The code in a repository connected to GitVelocity belongs to that customer, not to us.
- Anything not listed above is out of scope, including Render preview environments and
*.onrender.comhostnames.
Allowed testing
- Test only against accounts and organizations you own, and create no more than two test accounts. Sign them up with a real email address you can be reached at (a +security alias is fine), not a disposable one, and include those addresses in your report.
- Register no more than two OAuth clients, from your test accounts.
- Never access, modify or delete another organization's data. If you can see data that belongs to another organization, stop testing and report it to us straight away.
- Access only the minimum data needed to show the issue. Don't download, keep or share data that isn't yours, and delete anything you accessed once you've reported it. We may ask you to confirm you've deleted it.
- Don't run automated vulnerability scanners, and don't attempt denial of service. Manual testing with your own tools is fine.
- Don't register OAuth clients whose name, logo, client_uri or redirect domain imitates GitVelocity, Headline or any other company or product.
- Don't spam or social-engineer GitVelocity users or Headline staff.
- When you're done, delete your test accounts (Settings → Profile → Delete Account) and list the OAuth clients you registered in your report, so we can remove them.
Rewards
We don't currently run a formal bug bounty program. We evaluate every report we receive, and if we confirm that your finding is valid, we will get back to you about next steps.
Safe harbor
If you test GitVelocity in good faith and follow this policy, we won't take legal action against you for that testing. This doesn't cover third-party systems or conduct that breaks the law. If you're not sure whether something is allowed, ask us at support@headline.com before you test it.
How to report
Email support@headline.com. Put "Security" in the subject line, and include:
- Steps to reproduce the issue
- The affected URLs
- The impact: what an attacker could do with it
We follow coordinated disclosure. Keep the details private until we've agreed a disclosure date with you. That date is after a fix is deployed and any affected customers have been notified, and no later than 90 days after your report unless we agree an extension.
Our commitment
- We'll acknowledge your report within 5 business days.
- We'll tell you whether we can reproduce the issue, and let you know when a fix is released.