Reporting a security problem
Gallpack holds artists' work and collectors' orders, and it moves money. If you have found a way to see or change something you should not be able to, we want to hear it first.
Write to
security@tentapack.com -- read by the people who run Gallpack, not a queue. Say what you found, how to reproduce it, and what you think it could reach. A screenshot or a request log helps; a working exploit is not needed.
What happens next
- We acknowledge within 2 business days.
- We tell you what we found and when it is fixed; anything that touches money or personal data is treated as the most urgent thing we have (Gallpack_49's severities).
- We credit you here, by name or handle, if you would like that.
- There is no bounty programme yet. We say so plainly rather than imply one.
What we ask
- Test against your own accounts. Do not read, change or delete anyone else's data, and stop as soon as you have shown the problem exists.
- No denial of service, no spam, no social engineering of the people who run Gallpack or of artists and collectors.
- Give us a reasonable time to fix it before you publish; we will keep you informed.
Safe harbour
Research that follows the lines above is authorised. TentaPack LLC will not pursue or support legal action against you for it, and if a third party raises a claim over research done in good faith by these rules, we will say so on your behalf. This does not license anything beyond what is written here.
A product of TentaPack LLC · TentaPack LLC, Chicago, IL. A machine-readable copy of this page is at/.well-known/security.txt.