Security

Responsible
disclosure.

We take security seriously. If you discover a vulnerability in Dune Sale, please tell us before disclosing it publicly.

How to report

Email security@dunesale.com with a description of the issue, steps to reproduce, and any proof-of-concept code or screenshots. We’ll acknowledge within 48 hours on weekdays.

Scope

In scope:

  • dunesale.com and all subdomains
  • partner.dunesale.com (partner portal)
  • /api/* endpoints
  • Authentication flows (OTP, magic link, admin login)

Out of scope:

  • Denial-of-service testing without our written consent
  • Social engineering of Dune Sale staff
  • Physical security of Dune Sale offices
  • Vulnerabilities in our third-party providers (Vercel, Supabase, Resend, PostHog, Upstash) — report to them directly

Safe harbor

Research conducted in good faith following this policy will not result in legal action from Dune Sale. Please do not access, modify, or exfiltrate any partner data beyond the minimum needed to demonstrate the issue.

Response and resolution

  • Acknowledgment within 48 business hours
  • Initial assessment within 5 business days
  • Critical fixes within 7 days, non-critical within 30 days
  • Credit to reporter (if desired) once the fix is deployed

What we ask

  • Give us reasonable time to respond before public disclosure
  • Don’t exploit the issue beyond what’s needed to prove it exists
  • Don’t reveal user data — describe the pattern instead
  • Report one vulnerability per email so we can track each properly