Vulnerability disclosure policy
Seafarers.Pro holds crew personal data, certificates and vessel operational records. If you find a way to reach data you should not, we want to hear about it.
How to report
Email security@seafarers.pro. Reports in English or Russian are both fine. To let us reproduce the issue quickly, include:
- The affected URL, endpoint or app area, and the environment you tested (production, a trial tenant, or a vessel Edge node).
- Enough steps, requests or a short recording to reproduce the behaviour.
- What an attacker gains — which records they reach, whose data it is, and whether it crosses a tenant boundary.
- The account or tenant you used, so we can separate your testing from real traffic in the audit log.
What we commit to
Acknowledgement
Within 3 business days, from a person rather than an autoresponder.
Assessment
Within 10 business days: whether we reproduced it, our severity, and a fix timeline.
Fix and credit
Critical issues are patched as a priority. We credit reporters who want it, and never publish your details without asking.
In scope
- app.seafarers.pro — the crewing and fleet application
- api.seafarers.pro — the REST API under /api/v1, including authentication and tenant isolation
- admin.seafarers.pro — the platform administration console
- seafarers.pro — this marketing site
- The vessel Edge deployment and its shore sync endpoints
Out of scope
- Denial of service, volumetric or resource-exhaustion testing of any kind
- Findings from automated scanners with no demonstrated impact, and missing hardening headers on their own
- Social engineering, phishing, or physical access against our staff or customers
- Vulnerabilities in third-party services we integrate with — report those to their owners
- Anything requiring a compromised device, a rooted browser, or an already-privileged account acting within its permissions
Rules of engagement
This is production software used to crew working ships, and the records in it belong to real seafarers. While you are testing:
- Use your own trial tenant and your own test seafarers. Do not access, modify or download another tenant's data.
- If you do reach someone else's data, stop at the minimum needed to prove it, and say so in the report.
- Do not run destructive actions — no mass deletion, no payroll changes, no writes to a live vessel Edge node.
- Give us a reasonable chance to fix the issue before disclosing it publicly.
Safe harbour
If you follow this policy in good faith, we will treat your research as authorised, will not pursue or support legal action against you over it, and will work with you to understand and fix the issue. If a third party takes action over research that stayed inside this policy, we will make that authorisation clear. We do not currently run a paid bounty programme.