
Found a hole? We want to know
We pay researchers who help keep families’ vaults safe. Report in good faith and we promise a fast response, no lawyers, and public credit if you want it.
How to report.
Email us
security@endplan.com, include reproduction steps and impact.
We respond in 48h
Acknowledgement within two business days; triage verdict within seven.
We fix & disclose
Coordinated disclosure once patched. You publish when we do, or 90 days after report, whichever comes first.
Scope & rewards.
In Scope
The EndPlan web, iOS, and Android clients · the public API · our cryptographic libraries · the release mechanism. If it guards a vault, we want to know it’s broken.
Out of scope
Denial of service, social engineering of our staff, physical attacks, and third-party services we don’t operate.
Rewards
We reward genuine findings case by case, by severity and impact, vault-content exposure and release-mechanism bypasses sit at the top of the scale. Every valid report is credited, with your permission, whatever its size.
The best audit is a thousand curious strangers.
