Security Policy

Cubite welcomes reports of security vulnerabilities affecting cubite.io, any subdomain of cubite.io, and tenant sites hosted on the Cubite platform (including custom domains). This policy explains how to report issues and what to expect in return.

Reporting a vulnerability

Email security@cubite.io with:

  • A clear description of the issue and its impact.
  • Steps to reproduce, including affected URLs and any payloads.
  • Your name or handle if you would like to be credited.

Please do not open public GitHub issues, post on social media, or disclose the vulnerability to third parties before we have had a reasonable chance to remediate it.

What we ask of researchers

  • Test only against accounts and data you own. Do not access, modify, or exfiltrate data belonging to other users or tenants.
  • Do not perform denial-of-service, volumetric, or social-engineering attacks against Cubite staff, customers, or end users.
  • Do not run automated scanners that generate significant traffic without prior coordination.
  • Stop and report immediately if you encounter personal data; do not download or retain it.
  • Comply with all applicable laws.

What you can expect from us

  • Acknowledgement of your report within 3 business days.
  • A triage decision (accepted, duplicate, out-of-scope, or needs more information) within 10 business days.
  • Regular updates as we investigate and remediate.
  • Public credit in our release notes or a security advisory, if you would like it.
  • A good-faith commitment not to pursue legal action against researchers who follow this policy.

Scope

In scope:

  • cubite.io and all *.cubite.io subdomains.
  • Tenant sites hosted on Cubite, including custom domains pointed at the platform.
  • Cubite-operated APIs and authentication endpoints.

Out of scope:

  • Third-party services we integrate with (Hetzner, Cloudflare, Stripe, Cloudinary, Resend, Upstash, etc.) - report those directly to the vendor.
  • Findings from automated scanners without a demonstrable impact (e.g. missing security headers on non-sensitive endpoints, banner disclosure, weak ciphers on already-deprecated TLS versions).
  • Social engineering, physical attacks, and attacks against Cubite employees or infrastructure providers.
  • Denial-of-service, rate-limiting, and volumetric issues.
  • Self-XSS and issues that require a fully compromised victim browser or device.
  • Vulnerabilities in tenant-supplied content, themes, or custom CSS where the tenant administrator is the attacker.

Safe harbor

Research conducted in good faith and consistent with this policy is authorized. We will not pursue or support legal action against researchers for accidental, good-faith violations. If a third party initiates legal action against you for activity that complied with this policy, we will make it clear that your actions were authorized.

Contact

security@cubite.io security.txt

Support

How can we help?

Send us a message and we'll get back to you shortly.

We typically respond within 24 hours