Vulnerability Disclosure Policy
AhaSlides Security · Responsible disclosure · Last updated: 15 September 2026
Our commitment
We take the security of our users and their data seriously. We welcome reports from security researchers and will work with you to understand and resolve any issue quickly. We will not take legal action against you for security research conducted in good faith under this policy.
Scope
In scope
- ahaslides.com and its subdomains (for example presenter.ahaslides.com and audience.ahaslides.com)
- The AhaSlides web application, presenter and audience apps
Out of scope
- Denial-of-service (DoS/DDoS) and volumetric or traffic-flooding tests
- Social engineering of staff, users or contractors; physical attacks
- Spam, or findings from automated scanners without a demonstrated, exploitable impact
- Reports affecting only unsupported or end-of-life browsers
- Third-party services we do not control (raise those with the third party)
- Open (unauthenticated) audience access: the audience app deliberately lets anyone join a presentation and submit responses without an account or login, so that audiences can take part freely. Reports that the audience join or submission flow lacks authentication are not treated as vulnerabilities.
- Best-practice suggestions with no security impact (for example missing headers with no exploit, SPF/DMARC nitpicks, self-XSS, rate-limiting opinions). These are welcome, but not treated as vulnerabilities.
Rules of engagement
Please do:
- Report as soon as you find an issue, and give us reasonable time to fix it before disclosing publicly.
- Use only your own test accounts. Stop at proof-of-concept.
Please do not:
- Access, modify, download, or delete data that is not your own. To prove access, a screenshot or a minimal, redacted record is enough, so do not exfiltrate real user data.
- Degrade or interrupt our services, or run automated high-volume attacks.
- Publicly disclose the issue before we have confirmed it is resolved (see Coordinated disclosure).
How to report
Email security@ahaslides.com with:
- A clear description of the vulnerability and its impact.
- Step-by-step reproduction, including the affected URL or endpoint.
- Proof-of-concept (screenshots, a short video, or a minimal request), redacted.
- Your name or handle for credit (optional).
What you can expect from us
- Acknowledgement within 2 business days.
- A triage decision (valid, need-more-info, or out-of-scope) within 5 business days.
- Regular updates while we work on a fix, and notice when it is resolved.
- Public credit in our security acknowledgements, if you would like it.
Coordinated disclosure
We ask that you keep the details private until we confirm a fix is deployed, and coordinate any public write-up with us. Our target remediation window is 90 days; if we need longer we will tell you why.
Recognition
AhaSlides is a growing company and does not run a fixed, published paid bounty programme. Where a report is valid, original, and responsibly disclosed, we may, at our discretion, offer a token of appreciation and/or public credit as a thank-you.
Duplicate reports. Where several people report the same issue, the first reproducible report we receive is the one eligible for any reward. Later reporters of the same issue may still receive public credit if they add materially new information (for example a more severe impact, a better reproduction, or an additional affected surface).
Already-known issues. If we are already aware of an issue and have it logged internally before your report arrives, we will still acknowledge and thank you, but it will not be eligible for a reward. As with duplicates, we may offer public credit where your report adds materially new information.
We are always grateful for your help in keeping AhaSlides safe.