Security
Vulnerability Disclosure
Last updated: May 19, 2026
We take security seriously. If you’ve found a vulnerability in sabet.com, please report it privately so we can fix it before it gets exploited.
How to report
Email security@sabet.com with:
- A clear description of the issue
- Steps to reproduce
- What an attacker could realistically do with it
- Your handle if you’d like public credit on the patch
PGP is supported on request — reply to your initial report and we’ll send a public key.
What to expect
- Within 72 hours: initial acknowledgment that we received your report.
- Within 7 days: our assessment of severity and whether we can reproduce.
- Patch timing: critical issues typically within 24-48 hours; lower severity within 2-4 weeks.
- Public credit:if you’d like, we’ll credit you in the changelog once the fix ships.
Safe harbor
Good-faith security research is welcome. As long as you:
- Don’t access data that isn’t yours (your own test account is fine; another user’s is not)
- Don’t disrupt the service (no DoS, no mass scraping, no automated load testing)
- Don’t publicly disclosebefore we’ve had a reasonable chance to patch
- Stop and reportas soon as you’ve confirmed an issue exists — don’t exploit further
…we won’t pursue legal action against you for security research conducted in good faith. We’ll work with you to understand the issue, fix it, and credit your work.
Out of scope
The following typically aren’t actionable:
- Issues in third-party services (Clerk, Stripe, Vercel, Resend) — report those directly to the vendor
- Reports requiring physical access, social engineering, or credential stuffing
- Missing security headers without a demonstrable impact
- Self-XSS, clickjacking on pages without sensitive actions
- Username / email enumeration via auth flows
- Rate-limit gaps on public read endpoints (we’re aware and shipping fixes)
Bug bounty
We don’t currently run a formal bug bounty program. For high-impact findings we may offer a token of thanks (signed art, a credit on the site, occasional cash for severe issues) at our discretion. Report security issues because they should be reported — not for the reward.
Machine-readable contact
See /.well-known/security.txt for the RFC 9116 contact record (used by automated scanners and bug-bounty platforms).
Thank you for helping keep Sabet’s collectors and artists safe.
