Skip to main content

Security

Found a security issue? Tell us.

Last updated September 2026.

Report a vulnerability

Email support@bullyeah.com with a description of the issue, the steps to reproduce it, and its potential impact. This is the same inbox described on our Support page — a real person reads every message, and security reports get priority attention over general support questions.

We don't yet run a formal bug-bounty program or guarantee a specific response-time SLA. We do commit to acknowledging a good-faith report, investigating it, and telling you honestly what we found and fixed — not going silent.

Responsible disclosure

  • Give us a reasonable window to investigate and fix an issue before any public disclosure.
  • Don't access, modify, or exfiltrate another user's data — use a test account you control, or describe the issue without actually exploiting it against real accounts.
  • Don't run automated scanners, load tests, or denial-of-service traffic against production without asking first.
  • Test only against bullyeah.com / its API — not our infrastructure providers (Supabase, Render, Stripe, market-data vendors) directly.

We won't pursue legal action against anyone who reports a genuine vulnerability in good faith and follows the guidelines above.

What's already in place

Verifiable directly in this app's shipped code, not just asserted here:

  • A strict, per-request-nonce Content-Security-Policy (no unsafe-inline scripts), HSTS in production, X-Frame-Options / frame-ancestors denial, MIME-sniffing protection, and a locked-down Permissions-Policy.
  • HttpOnly, Secure session cookies in production — a script running on this page can't read your session token.
  • Rate limiting on write endpoints to slow down abuse and credential-stuffing attempts.
  • Passwords are never stored by BullYeah directly — authentication is delegated to Supabase, which handles hashing and storage.

What's honestly still missing

We'd rather list these plainly than let a strong header list above imply more maturity than exists:

  • No multi-factor authentication or passkey support yet.
  • No independent third-party security assessment or penetration test has been performed yet.
  • No formal, published incident-response runbook with named on-call ownership (see Status for what monitoring does exist today).
  • No paid bug-bounty program — reports are valued and acknowledged, but not currently compensated.

This page describes BullYeah's actual current security practices and process, not a target state or a marketing claim. It will be updated as real controls change — not on a schedule, and not ahead of what's actually shipped.