Responsible Disclosure
Last updated: 11 July 2026
We take the security of Squigggle seriously and welcome reports from security researchers who help us keep our users safe.
How to report
Please email security@squigggle.io with a description of the issue, the steps to reproduce it, and any supporting material (for example, screenshots or proof-of-concept code).
Our commitment to you (safe harbour)
If you make a good-faith effort to comply with this policy, we will not pursue or support legal action against you in relation to your research, and we will work with you to understand and resolve the issue promptly. We will acknowledge your report, keep you updated on our progress, and — if you wish — credit you once the issue is resolved.
Guidelines
- Act in good faith and avoid privacy violations, data destruction, or service disruption.
- Do not access, modify or delete data that does not belong to you; use only test accounts and your own data.
- Do not run automated scanning that degrades the Service, and do not perform denial-of-service testing.
- Give us a reasonable time to investigate and fix an issue before disclosing it publicly.
Out of scope
Social-engineering of our staff or users, physical attacks, denial-of-service attacks, and reports from automated tools without a demonstrated vulnerability are out of scope.
Scope
This policy covers our production website and Service at squigggle.io. Third-party services we rely on are covered by their own programmes.
Document control
- Version 2.0 — 11 July 2026 (current version)