Security researchers help make Cetera safer. If you believe you have found a security vulnerability in a Cetera system, please report it privately through our security report form.
This policy explains which systems and testing activities Cetera authorizes. It is not a bug-bounty program and does not promise payment or other compensation.
Systems Covered by This Policy
This policy applies only to the following systems operated by Delightful Development LLC as part of Cetera:
cetera.social;api.cetera.social;account.cetera.social;- the official Cetera applications for iOS and Android, when interacting with the Cetera services listed above; and
- any other system that Cetera expressly identifies in writing as covered by this policy.
Any domain, subdomain, application, service, or system not listed above is outside the scope of this policy.
Third-party products and services are not covered, even when Cetera uses, integrates with, or links to them. This includes infrastructure or services operated by hosting providers, Apple, Google, Microsoft, and other vendors. Please follow the applicable third party's security-reporting policy.
A third party may host an in-scope Cetera service. You may test the listed Cetera application surface under this policy, but you may not target the provider's infrastructure, accounts, control plane, or other services.
If you discover a possible vulnerability affecting Cetera through an out-of-scope system, you may still report it to us, but this policy does not authorize you to test that system.
What You May Do
When testing an in-scope system, you may:
- create and use Cetera accounts that belong to you;
- use test data that belongs to you or that you have permission to use;
- inspect requests and responses generated by your own use of Cetera;
- perform low-volume, non-disruptive manual or automated testing;
- test access controls between accounts that you own or have permission to use;
- inspect the official Cetera applications for the limited purpose of identifying a security vulnerability; and
- perform the minimum validation reasonably necessary to demonstrate that a vulnerability exists.
Do not access another person's account or information to prove that an issue is exploitable. A clear description, redacted evidence, or proof using your own accounts is sufficient.
What You May Not Do
This policy does not authorize you to:
- access, copy, alter, delete, retain, or disclose another person's information;
- access another person's account without their express permission;
- conduct denial-of-service, load, stress, or other testing that could degrade Cetera;
- use high-volume automated scanning or ignore applicable rate limits;
- perform credential stuffing, password spraying, brute-force attacks, phishing, or other social engineering;
- create spam, generate abusive traffic, or create accounts at scale;
- introduce malware or harmful code;
- establish persistence, install a backdoor, move laterally, or use a vulnerability to investigate other systems;
- test physical security, employees, contractors, personal devices, corporate accounts, or internal administrative systems;
- test a third-party service or infrastructure provider;
- use a vulnerability to harm Cetera, its users, or another person;
- demand payment or another benefit as a condition of withholding harmful activity or sensitive information; or
- publicly disclose credentials, personal information, secrets, or actionable exploit details that create a material risk of harm.
You must comply with applicable law. This policy does not authorize activity that Cetera cannot lawfully authorize.
When to Stop
Stop testing immediately if you:
- encounter another person's private or personal information;
- gain unexpected access to an account, administrative function, secret, credential, or internal system;
- cause or reasonably believe you may cause service instability, data loss, or another unexpected risk; or
- receive a request from Cetera to stop or modify your testing.
Do not continue exploring after reaching a stop condition. Do not download, retain, or share information you encounter other than the minimum redacted evidence reasonably needed to identify the issue. Report what happened privately through our security report form.
Reporting an Issue
Please submit reports through our security report form. A useful report includes:
- the affected website, API, application, or application version;
- a clear description of the issue and its potential impact;
- the steps needed to reproduce it;
- any request IDs, timestamps, or other non-sensitive diagnostic details;
- redacted screenshots or proof using accounts and data you own;
- whether you encountered another person's information or caused an unexpected effect; and
- a way to contact you if you would like a response.
Do not submit passwords, authentication tokens, private keys, another person's information, unredacted production data, or unnecessary copies of sensitive material.
You may choose not to provide contact information in your report, but we may be unable to ask questions or provide updates without a reliable contact method. Information submitted through the form is handled as described in our Privacy Policy.
How We Handle Reports
We will review reports and prioritize them based on their apparent impact and urgency. We may contact you for clarification or ask you to stop or modify testing.
Cetera is operated by a small team. We do not promise a particular acknowledgment, investigation, remediation, or disclosure timeline. Some reports may require additional investigation or coordination with a service provider.
Submitting a report does not promise payment, a reward, public acknowledgment, employment, or any other compensation.
Coordinated Disclosure
Please report vulnerabilities privately and give us a reasonable opportunity to investigate and protect users before publishing technical details.
We do not require an indefinite embargo or promise a fixed remediation deadline. We ask that you coordinate disclosure timing with us based on the severity of the issue, the risk to users, the availability of a fix, and any required third-party coordination.
Regardless of timing, do not publicly disclose credentials, personal information, secrets, or exploit details when doing so would create a material and avoidable risk of harm.
Authorization for Good-Faith Research
If you make a good-faith effort to comply with this policy while researching an in-scope Cetera system, Delightful Development LLC will consider your research authorized under Cetera's Terms of Service and Community Guidelines and will not initiate legal action against you solely for that research.
If a third party initiates legal action concerning research that we determine was conducted in accordance with this policy, we will, if reasonably requested, state that we considered the research authorized.
This authorization does not:
- bind a third party or government authority;
- authorize testing of a third party's systems;
- waive any rights or remedies concerning conduct outside this policy;
- protect unlawful conduct that Cetera cannot authorize; or
- prevent Cetera from restricting access or asking you to stop when reasonably necessary to protect Cetera, its users, or another person.
If you are unsure whether proposed testing is covered, contact us before proceeding.
Changes to This Policy
We may update this policy as Cetera and its services evolve. Changes apply prospectively from the date the updated policy is published and do not retroactively withdraw authorization for research conducted in a good-faith effort to comply with the policy in effect at the time.
We may ask you to stop or modify ongoing testing when reasonably necessary to protect Cetera, its users, or another person. You must comply with that request.