Security

Vulnerability disclosure

If you've found a security issue in the ShotSelect Mac app or in the website + worker fleet that backs it, please report it privately to the contact below. We respond within 72 hours and credit researchers in our changelog when they ask to be credited.

Last updated · 9 May 2026 Contact · [email protected] Response time · 72 hours
tl;dr. Email [email protected] with a clear repro. Don't publish until we've shipped a fix. We don't pay bounties yet, but we will credit you (with your permission) and reply fast.

In scope

Out of scope

How to report

Email [email protected] with:

If you need to send sensitive details, mention that in the first email and we'll arrange a Signal channel or PGP key.

What we promise

Safe-harbor and rules of engagement

Recognized researchers

None yet — this policy launched on 9 May 2026. Submit the first eligible report and you'll be the first name here.

Machine-readable contact: /.well-known/security.txt