Security

If you've found a security issue in UniMate, thank you. This page explains how to report it, what's in scope, and how we respond.

Reporting a vulnerability

Email security@getunimate.com with:

We aim to acknowledge within 48 hours and triage to a severity within 5 business days. No legal action will be taken against good-faith researchers who follow the policy below.

Scope

Out of scope: third-party services (Stripe, Freedom Pay, Telegram), social-engineering, DDoS, automated scanner output without a verified exploit, missing security headers on static asset domains.

Safe harbour

Researchers who follow this in good faith get safe harbour from us under DMCA + analogous laws.

Recognition

We don't run a paid bounty programme yet. Significant reports get public credit on this page (with your permission) and UniMate Pro for 12 months.

Our security practices

security.txt

Machine-readable contact: /.well-known/security.txt.

Contact: mailto:security@getunimate.com
Expires: 2027-01-01T00:00:00Z
Encryption: https://security.getunimate.com/pgp.asc
Preferred-Languages: en, ru
Canonical: https://security.getunimate.com/.well-known/security.txt
Policy: https://security.getunimate.com/

PGP

For sensitive reports, use our PGP key (coming soon at /pgp.asc). Until then, please send a regular email and we'll respond with a signed channel.