If you discover a security vulnerability in ExtractVibe, please report it responsibly.
Do not open a public issue. Instead, email security@extractvibe.com with:
- Description of the vulnerability
- Steps to reproduce
- Potential impact
We aim to acknowledge reports within 48 hours and will work with you on a fix before any public disclosure.
This policy covers the ExtractVibe codebase and the hosted service at extractvibe.com. It does not cover third-party dependencies — please report those to the respective maintainers.