Menu

Security Policy

How Space App handles security reports for the marketing site, consumer web app, mobile apps, and related services.

Responsible disclosure

If you believe you have found a security vulnerability in Space App, please report it privately so we can investigate and fix it before any public disclosure.

  • Do not access accounts, data, or systems you do not own or have permission to test.
  • Do not disrupt service, delete data, or attempt social engineering of staff or users.
  • Provide enough detail for us to reproduce the issue (steps, impact, affected surfaces).
  • Allow a reasonable time for us to respond and remediate before any public write-up.

How to report

Email security@spaceapp.klabs.ltd with a clear subject (for example, “Security report - Space App web”).

Machine-readable contact: /.well-known/security.txt

Scope

  • Space App marketing site (spaceapp.shop)
  • Space App web app (app.spaceapp.shop)
  • Space App mobile applications (iOS / Android)
  • Space App API and authenticated product surfaces you are authorized to use

Out of scope: third-party services (payment processors, store platforms, CDN providers), denial-of-service-only testing, and physical or social attacks.

Download Now