P Prop-Folio
Home For Business Help Contact
Download on iOS

Vulnerability Disclosure Policy

Effective: July 16, 2026 · Last updated: July 16, 2026

The short version

Found a security issue in Prop-Folio? Please email security@prop-folio.app. We’ll acknowledge within 3 business days and coordinate a fix. We won’t take legal action against good-faith researchers who follow this policy.

Reporting a vulnerability

If you discover a security vulnerability affecting the Prop-Folio mobile application, the prop-folio.app website, our Supabase backend, or any related infrastructure, please report it to us at security@prop-folio.app. Please include:

  • A description of the vulnerability and its potential impact.
  • Steps to reproduce, including any account credentials or test data you used.
  • Screenshots, code snippets, or proof-of-concept output where useful.
  • Your name and preferred contact method for follow-up (optional but appreciated).

What we will do

  • Acknowledge your report within 3 business days.
  • Investigate and validate the report as quickly as our resources allow.
  • Keep you informed of remediation progress on request.
  • Credit you in a public acknowledgment (with your permission) after the issue is resolved, if you would like recognition.

Safe-harbor commitment

We consider security research conducted in good faith and in accordance with this policy to be authorized activity, and we will not initiate legal action against you for such research. To qualify, please:

  • Only test against your own Prop-Folio account or accounts you have explicit permission to test.
  • Do not access, modify, or delete data belonging to other users.
  • Do not perform testing that would degrade the service for other users (denial-of-service, mass account creation, high-volume scanning).
  • Do not publicly disclose the vulnerability until we have had a reasonable opportunity to remediate.
  • Comply with all applicable law.

Out of scope

  • Social engineering against our employees or contractors.
  • Physical attacks against our offices or infrastructure.
  • Third-party services and integrations (Apple, Supabase, RevenueCat, Google, Anthropic) — please report those directly to the provider.
  • Reports generated purely from automated scanners without demonstrated impact.
  • Non-security bugs (please file those to support@prop-folio.app).

No bounty program

Prop-Folio does not currently offer monetary bug bounties. We welcome good-faith reports regardless and are happy to provide public acknowledgment.

Machine-readable contact

Our security contact information is also published at /.well-known/security.txt per RFC 9116.

Not legal advice

This policy is a description of how we handle security reports. Nothing on this page constitutes legal advice.

PProp-Folio

Real estate underwriting for individual investors. Informational analysis only — not personalized investment, tax, or legal advice.

Product
  • Home
  • Help
Legal
  • Privacy Policy
  • Terms of Use
  • DMCA Policy
  • Third-Party Notices
  • Security
© Winchester Realty & Holdings LLC. All rights reserved.