Security and vulnerability disclosure
Last updated: August 9, 2026
Report suspected vulnerabilities privately to contact@broomva.tech. Include the affected URL or component, reproduction steps, impact, and safe supporting evidence. Do not include unnecessary personal data.
Good-faith research
This policy covers the broomva.tech application and source code that Carlos D. Escobar-Valbuena controls. It does not authorize testing of Vercel, Neon, Stripe, AI providers, other third-party systems, or another user's account or data. Follow each provider's policy and report provider-specific findings to that provider.
Please avoid privacy violations, denial of service, social engineering, physical intrusion, data destruction, persistence, and access beyond the minimum needed to demonstrate the issue. Stop if you encounter personal data or secrets, tell us what was exposed, and do not retain or disclose it. To the extent within the operator's authority, we will not pursue legal action for good-faith research within this scope that follows this policy and applicable law.
What to expect
We aim to acknowledge a report within five business days, triage it, provide updates when practical, and coordinate disclosure. These are response targets, not a contractual SLA or bounty promise. Please give us reasonable time to investigate and remediate before public disclosure.
Current posture and limits
Broomva uses encrypted transport, authentication, authorization checks, monitoring, dependency scanning, and a coordinated reporting channel. This page does not claim a certification, penetration-test result, perfect security, database row-level security, or tamper-evident audit logging. Enterprise security commitments apply only in a signed agreement.
The machine-readable contact is at /.well-known/security.txt. Personal-data questions belong at the Privacy Policy.