Security & Vulnerability Disclosure
Last updated: 30 July 2026 · Draft for review
Reporting a vulnerability
If you believe you have found a security vulnerability, please report it privately to [security contact — TO BE SUPPLIED, e.g. security@sessiontwin.ai]. Please include enough detail to reproduce the issue and give us a reasonable time to fix it before any public disclosure.
What to expect
- We will acknowledge your report within a few business days.
- We will investigate, keep you informed of progress, and let you know when the issue is resolved.
- We will credit reporters who wish to be credited, once a fix is in place.
Scope and safe harbour
In-scope: sessiontwin.ai and the sessiontwin application. Out of scope:
the underlying Base44/Wix platform, GitHub, and other third-party services — report
those to the respective providers. Please act in good faith: do not access or modify
other users' data, do not degrade the service, and do not run automated attacks. We
will not pursue good-faith researchers who follow this policy.
How the product is built to be checkable
sessiontwin's ledger is signed with a key the backend never holds, and its integrity can be audited independently in the browser — see the ledger page. Note that integrity evidence proves a record was not altered; it does not prove the work is correct or secure (see the Terms, "What a verified ledger does — and does not — attest").
Known items under review
As part of preparing these documents, the following were flagged for the operator to verify (details in the internal review report):
- Whether the ledger-audit endpoint can return a private mission's records without authentication (depends on the platform's function-invocation defaults).
- Whether the platform analytics identifier and CDN monitoring require user consent.
Open questions for counsel / operator
- Finalise the security contact address and publish it.
- Decide whether to offer a
/.well-known/security.txtfile (recommended) pointing here. - Confirm the safe-harbour wording is compatible with Israeli law.