Security

Security disclosure

We take the security of Threadline Comments and related infrastructure seriously. If you believe you have found a vulnerability, please report it responsibly.

How to report

Email

Send details to security@threadline.io. Include steps to reproduce, affected URLs or endpoints, and impact assessment when possible.

Encrypted mail (optional)

Prefer encrypted mail? Request our current PGP fingerprint from security@threadline.io.

What to expect

  • Acknowledgement within 3 business days
  • An initial severity triage and follow-up questions if needed
  • Remediation timeline shared for confirmed issues
  • Credit in our changelog for valid reports (unless you prefer anonymity)

Scope

In scope: threadline.io, the comments API, embed widget, authentication, and publisher dashboard features that could expose user or publisher data.

Out of scope: social engineering, physical attacks, denial-of-service volume tests without prior approval, and reports that rely only on outdated browsers or third-party services we do not control.

Safe harbor

We will not pursue legal action against researchers who act in good faith, avoid privacy violations and data destruction, and give us a reasonable chance to fix issues before public disclosure.

Related: Privacy · Subprocessors · DPA · Status