Supported versions

Reports should concern the current website at savekindly.com or the most recent extension build supplied directly by SaveKindly for approved testing. Old local builds, third-party copies, and speculative future features are outside the supported scope.

Narrow extension permissions

The current preview manifest requests Chrome storage and alarms. Its host access is limited to local demonstration origins. Production storefront origins will only be added after they pass review and will be disclosed with the public build.

How to report a potential vulnerability

Email hello@savekindly.com with a concise description, the affected URL or component, reproduction steps, and the impact you observed. Use the subject “Security report”. The machine-readable contact is also available at /.well-known/security.txt.

What not to include

Do not send passwords, full payment-card details, authentication secrets, unrelated personal information, or data belonging to another person. Do not create purchases, attempt to access other accounts, disrupt service, or use destructive testing. A minimal proof is enough to begin a conversation.

What to expect

SaveKindly will acknowledge a responsible report when the mailbox is monitored, ask for clarification if needed, and prioritise remediation based on verified impact. This page does not promise a bounty, a fixed response deadline, or permission to test outside the stated boundaries.