Responsible Disclosure Program
Report Security Vulnerability
Cybersecurity Policy • security@ikcj.web.id • ikcj.web.id
We Value Ethical Security Researchers
Ikhlas CronJob is dedicated to maintaining the utmost security standards. If you discover a vulnerability in our platform, we deeply appreciate your responsible disclosure to help us mitigate the issue before public dissemination.
1. Program Scope & Eligibility
✓ In-Scope Vulnerabilities:
- Authentication bypass, MFA TOTP flaws, or Passkey bypasses.
- Supabase Row Level Security (RLS) leaks and authorization holes.
- Cross-tenant data exposure (BOLA / IDOR).
- Server-Side Request Forgery (SSRF) beyond expected scheduler behavior.
- Remote Code Execution (RCE) on worker executor instances.
- Stored Cross-Site Scripting (XSS) or SQL Injection vulnerabilities.
✕ Out-of-Scope Activities:
- Automated vulnerability scanner outputs lacking viable proof of concept.
- Volumetric Denial of Service (DDoS) against edge infrastructure.
- Social engineering or phishing attacks against personnel.
- Scenarios requiring physical device seizure or jailbreaking.
- Missing security headers with no demonstrable exploit path.
2. Response SLA & Resolution Timeline
1 - 2 Business DaysInitial acknowledgment and ticket assignment
3 - 5 Business DaysSeverity triage and remediation planning
Coordinated FixDeployment of patch & Hall of Fame credit
3. Responsible Disclosure Guidelines
- Never access, mutate, or destroy data belonging to other developers. Use your own test accounts.
- Avoid actions that degrade platform uptime for legitimate workloads.
- Give our engineering team reasonable time to patch vulnerabilities before any public disclosure.
Security Vulnerability Submission Form
You may submit directly via the form below or send an email report to security@ikcj.web.id.