Security at AppFrame
Prelaunch notice
This legal text reflects the current prelaunch setup and should receive a final legal review before the public launch.
If you believe you found a vulnerability affecting AppFrame, email [email protected]. Include reproduction steps, affected host and potential impact. Do not access other users’ data, degrade the service or publicly disclose an issue before we have had a reasonable opportunity to investigate.
Current controls
- Private storage, signed object URLs and workspace-scoped RLS.
- Server-only provider credentials and local JWT verification.
- Revision conflict checks and idempotent sensitive commands.
- Audited, time-limited support access.
- Container health checks, encrypted backups and restore testing.
Response
We will acknowledge credible reports, prioritise them according to impact and keep the reporter informed where practical. AppFrame does not currently operate a paid bug bounty.