Last updated: May 2026
SwingIQ is committed to keeping our users' data safe. We welcome responsible disclosure of security vulnerabilities. If you discover a security issue, we ask that you follow this coordinated disclosure process so we can fix it before it affects users.
Please do not open a public GitHub issue for security vulnerabilities. Public disclosure before remediation puts our users at risk.
Email the details to our security team. Do not open a public GitHub issue, post on social media, or disclose the vulnerability before we have had a chance to investigate and remediate.
We will confirm receipt of your report within 48 hours and provide an initial assessment within 5 business days.
Confirmed vulnerabilities will be remediated within 30 days for critical/high severity, and within 90 days for medium/low severity.
We will coordinate public disclosure timing with you. We are happy to credit your discovery in our release notes if you would like to be acknowledged.
Send your vulnerability report to our security team:
security@swingiq.app
(Replace this placeholder with your real security email before public launch — see SECURITY.md at the repository root.)
We will not pursue legal action against security researchers who:
This safe harbor applies to security research conducted in good faith under this policy. It does not apply to attackers who exploit vulnerabilities for malicious purposes.
| Severity | Acknowledgment | Target Fix |
|---|---|---|
| Critical | 48 hours | 7 days |
| High | 48 hours | 30 days |
| Medium | 48 hours | 60 days |
| Low | 48 hours | 90 days |