Security is part of how we design, build, and operate systems at Goobo Labs. This page explains how to report potential issues and what you can expect from us when you do.
If you believe you've found a security bug in a Goobo Labs product, project, or infrastructure, please let us know as soon as possible. We ask that you:
1. Avoid public disclosure until we've had a chance to investigate and ship a fix. 2. Only access data that clearly belongs to you, and never attempt to exfiltrate or destroy data. 3. Provide clear, reproducible steps so we can validate the issue quickly.
Please email security@goobolabs.so with:
– A short description of the issue and where you found it.
– Steps to reproduce, including sample payloads or screenshots if helpful.
– Any thoughts on potential impact or mitigation.
We aim to acknowledge security reports promptly, investigate them seriously, and keep you updated as we work on a fix. For high‑impact issues, we prioritize remediation and may reach out for additional details as needed.
This process covers Goobo Labs web properties, client‑facing systems we operate, and our public open‑source projects. If you're unsure whether something is in scope, contact us anyway and we'll clarify.