Skip to content

Security: CHI-Ecosystem/.github

SECURITY.md

Security Policy

CHI processes payments and personal data for live events, so we take security reports seriously and appreciate responsible disclosure.

Reporting a vulnerability

If you believe you have found a security vulnerability in any CHI product or service (chi.app, web.chi.app, backstage.chi.app, the CHI mobile apps, or our APIs):

  • Email: support@chi.app with the subject line SECURITY
  • Include a description of the issue, steps to reproduce, and the potential impact
  • If possible, include the affected URL/endpoint, request/response samples, and screenshots

Please do not open a public GitHub issue for security reports.

What to expect

  • We will acknowledge your report within 72 hours
  • We will keep you informed while we investigate and remediate
  • We will credit you for the finding if you would like (and the report is valid)

Guidelines

We ask that researchers:

  • Do not access, modify, or delete data that is not their own
  • Do not run automated scanners or load tests against production systems
  • Do not attempt social engineering, phishing, or physical attacks against CHI staff, customers, or events
  • Give us reasonable time to remediate before any public disclosure

Scope

Any CHI-operated system is in scope, including web applications, mobile apps, and public APIs. Third-party services we integrate with (payment providers, app stores) are out of scope — please report issues with those directly to the vendor.

Thank you for helping keep event-goers and organizers safe.

There aren't any published security advisories