Security & Responsible Disclosure
1. Reporting a Vulnerability
If you believe you have found a security problem in TransferNode, please email with "Security" in the subject line, a description of the issue, the steps to reproduce it, and its possible impact. We will confirm receipt and keep you updated while we fix it.
2. Please Do
- Use your own test transfers: Only test against transfers and accounts you created.
- Give us time: Allow us a reasonable time to fix the issue before telling anyone else.
3. Please Do Not
- Access other people's files: Do not open, download, change or delete files or data that are not yours, and do not try to guess or enumerate share links.
- Disrupt the service: Do not run denial-of-service attacks, spam, or automated scans that put load on the service.
- Use social engineering: Do not phish, trick or pressure our team or users.
4. Safe Harbor
If you follow this policy in good faith, we will not take legal action against you for your research. We do not currently run a paid bug bounty, but we are happy to thank researchers publicly if they wish.