Security researchers help make Cetera safer. If you believe you have found a security vulnerability in a Cetera system, please report it privately through our security report form.

This policy explains which systems and testing activities Cetera authorizes. It is not a bug-bounty program and does not promise payment or other compensation.

Systems Covered by This Policy

This policy applies only to the following systems operated by Delightful Development LLC as part of Cetera:

Any domain, subdomain, application, service, or system not listed above is outside the scope of this policy.

Third-party products and services are not covered, even when Cetera uses, integrates with, or links to them. This includes infrastructure or services operated by hosting providers, Apple, Google, Microsoft, and other vendors. Please follow the applicable third party's security-reporting policy.

A third party may host an in-scope Cetera service. You may test the listed Cetera application surface under this policy, but you may not target the provider's infrastructure, accounts, control plane, or other services.

If you discover a possible vulnerability affecting Cetera through an out-of-scope system, you may still report it to us, but this policy does not authorize you to test that system.

What You May Do

When testing an in-scope system, you may:

Do not access another person's account or information to prove that an issue is exploitable. A clear description, redacted evidence, or proof using your own accounts is sufficient.

What You May Not Do

This policy does not authorize you to:

You must comply with applicable law. This policy does not authorize activity that Cetera cannot lawfully authorize.

When to Stop

Stop testing immediately if you:

Do not continue exploring after reaching a stop condition. Do not download, retain, or share information you encounter other than the minimum redacted evidence reasonably needed to identify the issue. Report what happened privately through our security report form.

Reporting an Issue

Please submit reports through our security report form. A useful report includes:

Do not submit passwords, authentication tokens, private keys, another person's information, unredacted production data, or unnecessary copies of sensitive material.

You may choose not to provide contact information in your report, but we may be unable to ask questions or provide updates without a reliable contact method. Information submitted through the form is handled as described in our Privacy Policy.

How We Handle Reports

We will review reports and prioritize them based on their apparent impact and urgency. We may contact you for clarification or ask you to stop or modify testing.

Cetera is operated by a small team. We do not promise a particular acknowledgment, investigation, remediation, or disclosure timeline. Some reports may require additional investigation or coordination with a service provider.

Submitting a report does not promise payment, a reward, public acknowledgment, employment, or any other compensation.

Coordinated Disclosure

Please report vulnerabilities privately and give us a reasonable opportunity to investigate and protect users before publishing technical details.

We do not require an indefinite embargo or promise a fixed remediation deadline. We ask that you coordinate disclosure timing with us based on the severity of the issue, the risk to users, the availability of a fix, and any required third-party coordination.

Regardless of timing, do not publicly disclose credentials, personal information, secrets, or exploit details when doing so would create a material and avoidable risk of harm.

Authorization for Good-Faith Research

If you make a good-faith effort to comply with this policy while researching an in-scope Cetera system, Delightful Development LLC will consider your research authorized under Cetera's Terms of Service and Community Guidelines and will not initiate legal action against you solely for that research.

If a third party initiates legal action concerning research that we determine was conducted in accordance with this policy, we will, if reasonably requested, state that we considered the research authorized.

This authorization does not:

If you are unsure whether proposed testing is covered, contact us before proceeding.

Changes to This Policy

We may update this policy as Cetera and its services evolve. Changes apply prospectively from the date the updated policy is published and do not retroactively withdraw authorization for research conducted in a good-faith effort to comply with the policy in effect at the time.

We may ask you to stop or modify ongoing testing when reasonably necessary to protect Cetera, its users, or another person. You must comply with that request.