Chính sách tiết lộ lỗ hổng
AhaSlides Security · Responsible disclosure · Last updated: 15 September 2026
Cam kết của chúng tôi
We take the security of our users and their data seriously. We welcome reports from security researchers and will work with you to understand and resolve any issue quickly. We will not take legal action against you for security research conducted in good faith under this policy.
Phạm vi
In scope
- ahaslides.com and its subdomains (for example người dẫn chương trình.ahaslides.com và khán giả.ahaslides.com)
- The AhaSlides web application, presenter and audience apps
Ra khỏi phạm vi
- Denial-of-service (DoS/DDoS) and volumetric or traffic-flooding tests
- Social engineering of staff, users or contractors; physical attacks
- Spam, or findings from automated scanners without a demonstrated, exploitable impact
- Reports affecting only unsupported or end-of-life browsers
- Third-party services we do not control (raise those with the third party)
- Open (unauthenticated) audience access: the audience app deliberately lets anyone join a presentation and submit responses without an account or login, so that audiences can take part freely. Reports that the audience join or submission flow lacks authentication are not treated as vulnerabilities.
- Best-practice suggestions with no security impact (for example missing headers with no exploit, SPF/DMARC nitpicks, self-XSS, rate-limiting opinions). These are welcome, but not treated as vulnerabilities.
Quy tắc tham gia
Vui lòng do:
- Report as soon as you find an issue, and give us reasonable time to fix it before disclosing publicly.
- Use only your own test accounts. Stop at proof-of-concept.
Vui lòng không:
- Access, modify, download, or delete data that is not your own. To prove access, a screenshot or a minimal, redacted record is enough, so do not exfiltrate real user data.
- Degrade or interrupt our services, or run automated high-volume attacks.
- Publicly disclose the issue before we have confirmed it is resolved (see Tiết lộ phối hợp).
Làm thế nào để báo cáo
Email security@ahaslides.com với:
- A clear description of the vulnerability and its impact.
- Step-by-step reproduction, including the affected URL or endpoint.
- Proof-of-concept (screenshots, a short video, or a minimal request), redacted.
- Your name or handle for credit (optional).
Những gì bạn có thể mong đợi từ chúng tôi
- Lời cảm ơn ở trong 2 ngày làm việc.
- A triage decision (valid, need-more-info, or out-of-scope) within 5 ngày làm việc.
- Regular updates while we work on a fix, and notice when it is resolved.
- Public credit in our security acknowledgements, if you would like it.
Tiết lộ phối hợp
We ask that you keep the details private until we confirm a fix is deployed, and coordinate any public write-up with us. Our target remediation window is 90 ngày; if we need longer we will tell you why.
Công nhận
AhaSlides is a growing company and does not run a fixed, published paid bounty programme. Where a report is valid, original, and responsibly disclosed, we may, at our discretion, offer a token of appreciation and/or public credit as a thank-you.
Duplicate reports. Where several people report the same issue, the first reproducible report we receive is the one eligible for any reward. Later reporters of the same issue may still receive public credit if they add materially new information (for example a more severe impact, a better reproduction, or an additional affected surface).
Already-known issues. If we are already aware of an issue and have it logged internally before your report arrives, we will still acknowledge and thank you, but it will not be eligible for a reward. As with duplicates, we may offer public credit where your report adds materially new information.
We are always grateful for your help in keeping AhaSlides safe.