OverviewReporting a VulnerabilityScopeResearch GuidelinesOut of ScopeOur CommitmentsConfidentialityRewardsSafe HarborContact Information

BlogChangelogPricingDocsConsole

Supermemory·Legal

Responsible Disclosure Policy

Effective July 11, 2026dhravya@supermemory.com

Overview

Supermemory takes the security of our Services and user data seriously. This Responsible Disclosure Policy explains how security researchers and users can report suspected vulnerabilities to us in a safe, coordinated, and constructive way.

If you believe you have found a security vulnerability in Supermemory, please report it promptly and give us a reasonable opportunity to investigate and remediate it before publicly disclosing details.

Reporting a Vulnerability

Please email vulnerability reports to dhravya@supermemory.com.

Include enough information for us to reproduce and understand the issue, such as:

  • A clear description of the vulnerability and its potential impact
  • The affected product, endpoint, domain, repository, or integration
  • Steps to reproduce, proof-of-concept code, screenshots, or logs, where safe to share
  • Any accounts, workspaces, or test data used during your research
  • Your preferred contact information for follow-up

Do not include sensitive personal data, secrets, access tokens, or customer content unless it is strictly necessary to demonstrate the issue.

Scope

This policy applies to security vulnerabilities affecting Supermemory-operated services, including:

  • Supermemory web applications and dashboards
  • Supermemory APIs and hosted infrastructure
  • Official Supermemory integrations, connectors, and plugins
  • Authentication, authorization, data access, and data isolation controls
  • Public repositories owned by Supermemory, where the issue affects Supermemory users or infrastructure

Third-party services, platforms, and dependencies are only in scope where the vulnerability is caused by Supermemory's implementation or configuration.

Research Guidelines

When conducting research, you agree to:

  • Use only accounts, workspaces, data, and systems that you own or are authorized to test
  • Avoid accessing, modifying, deleting, or exfiltrating data that does not belong to you
  • Stop testing and notify us immediately if you encounter non-public user data, secrets, credentials, or internal systems
  • Avoid service degradation, spam, social engineering, phishing, physical attacks, or denial-of-service testing
  • Comply with applicable laws and this policy

Out of Scope

The following are generally out of scope unless they demonstrate a concrete, exploitable security impact:

  • Automated scanner output without validation or a practical attack path
  • Missing security headers or cookie flags that do not create a meaningful exploit
  • Clickjacking on pages without sensitive actions
  • Rate limiting, brute force, or account enumeration reports without material impact
  • Self-XSS, logout CSRF, or issues requiring unlikely user interaction
  • Publicly disclosed vulnerabilities in third-party software without evidence that Supermemory is affected
  • Denial-of-service, load testing, spam, phishing, social engineering, or physical security testing

Our Commitments

When you follow this policy, we will make a good faith effort to:

  • Acknowledge receipt of your report within a reasonable timeframe
  • Review the report and ask clarifying questions where needed
  • Validate, prioritize, and remediate confirmed vulnerabilities based on severity and risk
  • Keep you informed of meaningful status changes when appropriate
  • Credit you for responsible disclosure if you request recognition and disclosure is appropriate

Confidentiality

Please keep vulnerability details confidential until we have investigated and addressed the issue. Public disclosure should be coordinated with Supermemory and should not include user data, secrets, exploit code that enables active abuse, or information that would materially increase risk to users.

Rewards

Supermemory does not currently operate a public bug bounty program and does not guarantee monetary rewards for vulnerability reports. We may, at our sole discretion, provide recognition or other thanks for high-quality reports.

Safe Harbor

We will not initiate legal action against security research conducted in good faith, in accordance with this policy, and without harm to Supermemory, our users, or third parties. This safe harbor does not apply to activity that violates the law, causes service disruption, accesses or discloses data without authorization, or exceeds the scope and guidelines in this policy.

Contact Information

For security vulnerability reports, contact us at:

Email: dhravya@supermemory.com

Last Updated: July 11, 2026

Supermemory © 2026BlogChangelogPricingDocsConsolePrivacyTermsResponsible disclosureSan Francisco