We take security seriously and welcome reports from the researcher community. This page explains how to report a vulnerability, what's in scope, what we commit to, and the safe-harbor protections you have when you follow this policy in good faith.

✓ Report to security@mydiygarage.com
✓ Machine-readable pointer: /.well-known/security.txt
✓ Critical & High issues patched within 72 hours of confirmation
✓ Good-faith research covered by our safe-harbor terms below

How to report

Send a report to security@mydiygarage.com. For sensitive reports, you may instead open a GitHub private security advisory — this gives us an encrypted, tracked channel without needing our PGP key.

Please include:

We reply from security@mydiygarage.com. If you don't hear back within the acknowledgement window below, please resend from a different address or open a private advisory — it may have been caught in filtering.

What we commit to

Business day = US/Central, Monday–Friday, excluding US federal holidays. The clock starts when your report arrives.

Severity Acknowledge Triage complete Patch in production
Critical ≤ 1 business day ≤ 2 business days ≤ 72 hours from confirmation
High ≤ 2 business days ≤ 3 business days ≤ 72 hours from confirmation
Medium ≤ 3 business days ≤ 5 business days ≤ 30 days from confirmation
Low ≤ 5 business days ≤ 10 business days Next reasonable release

"Confirmation" means we've reproduced the issue (or accepted a compelling proof-of-concept) and assigned a severity. If a fix requires coordinating with a third party or a data migration and 72 hours isn't feasible, we'll tell you why and give you a realistic target.

In scope

Out of scope

The following are outside this policy and will be closed at triage with a pointer here — please don't spend your time on them:

Safe harbor

If you make a good-faith effort to comply with this policy, we will:

  1. Consider your research authorized under our Terms of Service and the U.S. Computer Fraud and Abuse Act (CFAA), and we will not pursue civil action or refer the matter for prosecution.
  2. Waive claims under the Digital Millennium Copyright Act (DMCA) for the research activity described in this policy.
  3. Work with you to understand and resolve the issue quickly, and — if you'd like credit — publicly acknowledge your contribution when we disclose.

Good-faith research means: you tested only against your own account (or a synthetic one you created), you did not access, modify, or destroy anyone else's data, you did not disrupt service, and you gave us a reasonable window to fix the issue before publishing.

Coordinated disclosure

Our default disclosure window is 90 days from confirmation. We may agree with you to publish sooner (e.g., a fix ships fast) or later (e.g., a third-party vendor needs more time). If we observe active in-the-wild exploitation, we'll publish mitigations first and detailed disclosure after the fix is deployed.

Public disclosure typically appears in a note on our What's New page and, when appropriate, a GitHub Security Advisory that credits you (with your consent) and links to the assigned CVE.

Rewards

We do not currently run a paid bug-bounty program. We do offer credit in the release note and the security advisory when you'd like it, and — for exceptional finds — we're happy to send a thank-you.

Questions

For anything not covered here, write to security@mydiygarage.com. For general contact, see hello@mydiygarage.com. Privacy questions go to privacy@mydiygarage.com and legal to legal@mydiygarage.com.

Nielsen Digital, LLC
c/o Northwest Registered Agent, LLC
5900 Balcones Drive, Suite 100
Austin, TX 78731
United States