Vulnerability disclosure policy
This policy explains how to report a potential security issue, what testing is permitted, and how Screenpipe evaluates reports. It is not blanket permission to scan or test production systems.
Last updated July 29, 2026
Before you test
- Use only accounts, workspaces, devices, and data that you own or have explicit permission to use.
- Keep requests manual and low volume. Automated scanning, brute force, enumeration, request flooding, load testing, and denial-of-service testing are not permitted.
- Stop at the minimum proof needed. If you encounter another person's data or credentials, stop immediately, do not copy or retain them, and report the issue.
- Stop testing if you receive a 403, 429, block, warning, or a request from Screenpipe. Do not try to bypass the control.
How to report
Email one complete report to support@screenpi.pe with a subject beginning with [security]. Use one thread per distinct root cause; combine affected endpoints and duplicate symptoms in that thread.
Include the affected asset, a concise impact statement, reproducible steps using your own account or data, relevant timestamps and request IDs, and a minimal proof of concept. Explain the real trust boundary crossed rather than relying on a scanner rating or CVSS score alone.
Do not send:
passwords, session tokens, private keys, customer data, unnecessary personal data, or bank, PayPal, or cryptocurrency payment details. We request payment information only after a reward has been approved in writing.
Scope
Permitted without advance approval
- Normal browser interaction with public screenpipe.com pages.
- Low-volume manual testing of screenpipe.com flows using accounts and workspaces you own.
- Source review and local testing of the Screenpipe repository on systems and data you own.
Written approval required
- api.screenpi.pe and any API, admin, internal, monitoring, or non-public endpoint.
- Automated tools or more than low-volume manual requests.
- Any testing involving another user, organization, workspace, device, or data set.
What we prioritize
We prioritize findings with demonstrated real-world impact, especially:
- Cross-account or cross-organization data access.
- Authentication bypass, session hijacking, or credential exposure.
- Remote code execution or server-side injection.
- Authorization failures in cloud sync or hosted services.
- Material failures of Screenpipe's capture, privacy, or storage boundaries.
Out of scope
The following are prohibited or normally not eligible unless you demonstrate a distinct, material security impact:
- Automated scanning, brute force, credential stuffing, enumeration, spam, request flooding, load testing, or denial of service.
- Social engineering, phishing, physical attacks, malware, persistence, lateral movement, or accessing or changing data that is not yours.
- Missing security headers, cookie attributes on non-sensitive cookies, TLS or cipher preferences, and DNS or email-authentication records without a working exploit and demonstrated impact.
- A missing rate limit without a demonstrated authorization bypass, account compromise, or material availability impact.
- Clickjacking on pages with no sensitive action, self-XSS, tabnabbing, version disclosure, and other theoretical issues.
- Outdated dependencies without a reachable proof of concept, already known issues, duplicate reports, and multiple reports caused by the same root issue.
- Third-party services, including trust.screenpipe.com, authentication-provider infrastructure, hosting providers, and services that Screenpipe does not control.
What to expect
- We aim to acknowledge a complete report within 5 business days.
- Screenpipe determines validity, severity, and impact. A reporter-provided severity or CVSS score is input, not a decision.
- We aim to provide an initial eligibility decision within 30 calendar days when the report is reproducible and complete.
- Do not open duplicate threads or send status requests more than once every 14 days after acknowledgment.
- Reports that are prohibited, out of scope, incomplete, or duplicative may be closed without further response.
Rewards
Screenpipe does not operate a public bug bounty and does not promise payment for unsolicited testing or reports. We may, at our sole discretion, offer a reward for a significant, previously unknown, valid vulnerability that follows this policy. Out-of-scope, prohibited, duplicate, hardening-only, and scanner-only reports are not eligible.
A reward exists only after Screenpipe approves it in writing. Do not send payment details before that decision. Reward decisions are separate from remediation and may not be used to pressure or delay coordinated disclosure.
Coordinated disclosure
Keep vulnerability details confidential while we investigate and remediate. Do not publish, sell, or share the finding with third parties before Screenpipe confirms remediation or agrees to a disclosure date. For a valid report we will work with you toward a reasonable timeline, normally within 90 days of our acknowledgment.
Safe harbor
If you make a good-faith effort to comply with this policy, we will treat your research on Screenpipe-controlled systems as authorized and will not initiate legal action related to that research. This does not authorize activity outside the scope above, bind third parties, or waive your obligation to comply with applicable law.
If you are unsure whether a test is permitted, email us first and wait for written authorization before proceeding.