CHI processes payments and personal data for live events, so we take security reports seriously and appreciate responsible disclosure.
If you believe you have found a security vulnerability in any CHI product or service (chi.app, web.chi.app, backstage.chi.app, the CHI mobile apps, or our APIs):
- Email: support@chi.app with the subject line
SECURITY - Include a description of the issue, steps to reproduce, and the potential impact
- If possible, include the affected URL/endpoint, request/response samples, and screenshots
Please do not open a public GitHub issue for security reports.
- We will acknowledge your report within 72 hours
- We will keep you informed while we investigate and remediate
- We will credit you for the finding if you would like (and the report is valid)
We ask that researchers:
- Do not access, modify, or delete data that is not their own
- Do not run automated scanners or load tests against production systems
- Do not attempt social engineering, phishing, or physical attacks against CHI staff, customers, or events
- Give us reasonable time to remediate before any public disclosure
Any CHI-operated system is in scope, including web applications, mobile apps, and public APIs. Third-party services we integrate with (payment providers, app stores) are out of scope — please report issues with those directly to the vendor.
Thank you for helping keep event-goers and organizers safe.