Security
How to report a vulnerability or security incident.
Reporting a vulnerability
If you believe you have found a security vulnerability in BorderLens, please let us know as soon as possible. We take all reports seriously and will investigate promptly.
Email [email protected] with "Security vulnerability report" in the subject line. Please include:
- A description of the vulnerability and its potential impact
- Steps to reproduce or proof-of-concept
- Any relevant URLs, request/response data, or screenshots
We will acknowledge your report within 2 business days and keep you informed as we investigate and resolve the issue.
Responsible disclosure
We ask that you give us reasonable time to address a reported vulnerability before disclosing it publicly. We will not take legal action against researchers who report issues in good faith and follow this process.
Scope
Reports are in scope for the following:
- app.borderlens.io — the BorderLens merchant dashboard
- api.borderlens.io — the BorderLens API
- borderlens.io — this marketing site
Out of scope: denial-of-service attacks, social engineering, and issues in third-party services we depend on (report those to the relevant vendor).