If you discover a security vulnerability within ClipCash, please report it responsibly.
Do not open a public GitHub issue for security vulnerabilities.
Instead, please send an email to security@clipcash.io with the following details:
- Description of the vulnerability
- Steps to reproduce
- Potential impact
- Any mitigation suggestions
We will acknowledge your report within 48 hours and work with you to resolve the issue promptly.
We actively maintain the latest release and the previous major version. Security patches are applied to supported versions.
- Use strong, unique passwords for all accounts
- Enable MFA for sensitive operations
- Keep your API tokens secure and rotate them regularly
- Review access logs periodically
We follow a coordinated disclosure process. Once a fix is deployed, we will publish a security advisory and credit the reporter (unless they wish to remain anonymous).