Security
Last updated: August 1, 2026
If you have found a security vulnerability in Spanli, we want to hear about it. This page explains how to tell us, what to include, and what we will do.
Reporting a vulnerability
Email security@spanli.com.
Please report privately and give us a reasonable chance to fix the issue before you discuss it publicly.
If you want to encrypt your report, say so in a first message and we will arrange a key with you.
We do not run a bug bounty
We want to be straightforward about this before you spend time on it: Spanli does not operate a paid bug bounty programme and we do not use HackerOne, Bugcrowd or any other bounty platform. We do not pay for reports, and we cannot promise a reward, swag or a letter of recommendation.
What we do offer is a real person reading your report, a fix, and public credit if you want it and the finding warrants it. If that is not worth your time, we understand.
What to include
- What the issue is, and what an attacker could achieve with it.
- Where it is: the URL, endpoint or feature, and which environment you tested against.
- How to reproduce it, step by step, with the exact requests or payloads. A short proof of concept is worth more than a long description.
- What you observed: responses, screenshots, log excerpts.
- When you tested, and the account or project you used so we can find it in our logs.
- How to credit you, if you want to be named.
Testing safely
Research is welcome as long as it stays within the boundaries below. If you stay inside them and report in good faith, we will treat your research as authorised and we will not pursue legal action over it.
Please do not:
- access, modify, download or delete data belonging to anyone other than yourself. If a vulnerability exposes someone else’s data, stop as soon as you have confirmed it and tell us;
- degrade or disrupt the service, including denial of service tests, load testing, or exhausting AI credits or other resources;
- run automated scanners at scale against our systems, which we cannot distinguish from an attack;
- use social engineering, phishing or physical intrusion against our staff, our customers or our providers;
- attack our third-party providers directly. Report an issue in their product to them;
- publish the issue, or hold it for release at a conference or in a write-up, before we have fixed it;
- demand payment in exchange for withholding a report. That is not a disclosure, and we will treat it as extortion.
Use your own account and your own test project. Create a second free account if you need two parties to demonstrate an issue.
What we will do
- Acknowledge your report, normally within two business days.
- Assess it and tell you whether we consider it a vulnerability, and roughly how serious we think it is, normally within ten business days.
- Fix what we accept, prioritised by severity, and tell you when it is done.
- Credit you if you would like to be named.
- Notify affected customers and any relevant authority where the law requires it.
These are the timelines we work to, not a contractual commitment. We are a small team.
Out of scope
The following are usually not treated as vulnerabilities, though we will still read a report that shows real impact:
- findings from an automated scanner with no demonstrated exploit;
- missing security headers, cookie flags or TLS configuration preferences with no exploitable consequence;
- issues that require a compromised device, a malicious browser extension, or physical access to a signed-in machine;
- email configuration findings such as SPF, DKIM or DMARC policy strength, and reports of email spoofing without a working demonstration;
- rate limiting on endpoints where the consequence is only nuisance;
- content on a website built by one of our customers. That is an abuse report, not a security report, and belongs on our abuse page;
- behaviour of the AI assistant that produces low-quality or unexpected output but does not cross a security boundary.
How we protect the service
A summary of the measures we take is in section 10 of our Privacy Policy. If you are evaluating Spanli for your organisation and need more detail, write to support@spanli.com.