Security disclosure
We take the security of Threadline Comments and related infrastructure seriously. If you believe you have found a vulnerability, please report it responsibly.
How to report
Send details to security@threadline.io. Include steps to reproduce, affected URLs or endpoints, and impact assessment when possible.
Prefer encrypted mail? Request our current PGP fingerprint from security@threadline.io.
What to expect
- Acknowledgement within 3 business days
- An initial severity triage and follow-up questions if needed
- Remediation timeline shared for confirmed issues
- Credit in our changelog for valid reports (unless you prefer anonymity)
Scope
In scope: threadline.io, the comments API, embed widget, authentication, and publisher dashboard features that could expose user or publisher data.
Out of scope: social engineering, physical attacks, denial-of-service volume tests without prior approval, and reports that rely only on outdated browsers or third-party services we do not control.
Safe harbor
We will not pursue legal action against researchers who act in good faith, avoid privacy violations and data destruction, and give us a reasonable chance to fix issues before public disclosure.
Related: Privacy · Subprocessors · DPA · Status