Vulnerability Disclosure Policy

Last updated September 1st, 2026

1Reporting a vulnerability

Email security reports to hello@123sudo.com. Please include enough detail for us to reproduce the issue: the affected app or service, the version, the steps you took, and what you observed. A proof of concept helps more than a description.

Please report privately and give us a chance to fix the issue before publishing.

We reward reports that lead to a fix. There is no fixed table and no automatic entitlement: what we offer depends on the severity of the issue and the quality of the report, and can be a licence, AI credits or a cash payment. We will tell you what we are offering once we have assessed the report, and you are free to decline it.

2What is in scope

The 9xbuddy, 9xconvert and 9xchat desktop and mobile apps, and the services they depend on: 123sudo.com, docs.123sudo.com, api.123sudo.com, ai.123sudo.com, gw.123sudo.com, relay.123sudo.com, update.123sudo.com and status.123sudo.com.

If you find something outside that list on infrastructure we run, tell us anyway. We may not be able to act on it, but we would rather know.

3What is out of scope

Services we do not operate, including Cloudflare, Google Play, the App Store and our payment providers. Report those to the vendor, who can actually fix them.

Also out of scope: findings with no demonstrated impact, such as missing security headers, version disclosure or weak TLS suites on their own; volumetric or denial-of-service testing; spam and social engineering of our staff or users; and anything requiring physical access to a device.

4Safe harbour

If you make a good-faith effort to follow this policy during your research, we will treat your research as authorised, work with you to understand and fix the issue quickly, and we will not pursue or support legal action against you over it.

Good faith means testing only against accounts and data that are yours, stopping as soon as you have confirmed a problem, and never accessing, changing, deleting or keeping anyone else's data. If you are unsure whether a test is acceptable, ask us before running it.

5What to expect from us

We aim to acknowledge a report within 3 business days and to tell you what we intend to do about it once we have assessed it. We are a small team, so a fix may take longer than an acknowledgement, and we will say so rather than go quiet. We are happy to credit you when the fix ships, if you would like that.

6Already known

One finding comes up often enough to answer here: our apps carry a shared secret used to sign requests. It identifies which app is calling; it does not authorise anything on its own. Every expensive operation behind it has its own ownership check, rate limit and spending cap, and billing uses a separate secret that is never given to a client. We have assessed this and accepted it, so it is not a new report — but if you can show it unlocking something it should not, we very much want to hear from you.