Security

How to report a vulnerability or security incident.

Reporting a vulnerability

If you believe you have found a security vulnerability in BorderLens, please let us know as soon as possible. We take all reports seriously and will investigate promptly.

Email [email protected] with "Security vulnerability report" in the subject line. Please include:

  • A description of the vulnerability and its potential impact
  • Steps to reproduce or proof-of-concept
  • Any relevant URLs, request/response data, or screenshots

We will acknowledge your report within 2 business days and keep you informed as we investigate and resolve the issue.

Responsible disclosure

We ask that you give us reasonable time to address a reported vulnerability before disclosing it publicly. We will not take legal action against researchers who report issues in good faith and follow this process.

Scope

Reports are in scope for the following:

  • app.borderlens.io — the BorderLens merchant dashboard
  • api.borderlens.io — the BorderLens API
  • borderlens.io — this marketing site

Out of scope: denial-of-service attacks, social engineering, and issues in third-party services we depend on (report those to the relevant vendor).