Security and Vulnerability Disclosure Policy
1. Purpose
Cask.Directory takes the security of its platform and of its users' data seriously. If you believe you have found a vulnerability, please report it responsibly by following this policy.
2. Scope
- The https://cask.directory website and its pages
- The APIs exposed under https://cask.directory/api
The service is continuously deployed: only the version running in production is supported.
Out of scope:
- Third-party services we rely on (payments, email delivery, hosting, database, bot protection), which should be reported to their vendors directly
- Denial of service attacks, spam and social engineering
3. How to Report a Vulnerability
Send an email to contact@cask.directory with the subject "Security" and the following information:
- The affected URL or route
- A description of the vulnerability and its impact
- Steps to reproduce it
Please do not report vulnerabilities through public channels (social networks, forums).
4. Our Commitments
- Acknowledgment within 5 business days
- Initial assessment of the vulnerability within 15 days
- Updates on the fix until it is deployed to production
We do not run a paid bug bounty program.
5. Rules of Engagement
- No destructive testing and no load testing
- Do not access, modify or delete other users' data; only use your own test accounts
- Stop testing and notify us as soon as you access data that does not belong to you
- Do not disclose the vulnerability before it is fixed
6. Good Faith
We will not pursue legal action against anyone who reports a vulnerability in good faith and in accordance with this policy.

