Vulnerability Disclosure Policy
Last updated September 30, 2026
We want Tandem to be safe for everyone who builds on it, human or agent. If you believe you have found a security vulnerability in launchtandem.com, the Tandem portal, or any Tandem-operated service, please tell us. We appreciate good-faith research and will work with you to understand and fix the issue.
How to report
Email security@launchtandem.com with:
- A description of the issue and its potential impact.
- The affected host, URL, or component.
- Steps to reproduce, or a proof of concept.
- How you would like to be credited, if at all.
Please write in English. Our machine-readable contact details are published at /.well-known/security.txt.
What to expect
- We aim to acknowledge your report within 3 business days.
- We will keep you updated as we investigate, and let you know when the issue is resolved.
- With your permission, we are happy to credit you once a fix ships.
Guidelines
When researching, please:
- Only test against accounts and organizations you own or have explicit permission to test.
- Avoid accessing, modifying, or deleting other people’s data. If you encounter it, stop, and include only what is needed to demonstrate the issue in your report.
- Do not degrade the service for others: no denial-of-service, load or volumetric testing, spam, or social engineering of our staff or customers.
- Give us reasonable time to fix the issue before disclosing it publicly.
Safe harbor
If you make a good-faith effort to follow this policy, we will consider your research authorized, will not pursue legal action against you for it, and will work with you to resolve the issue quickly. This policy does not authorize testing of third-party services we use; follow those providers’ own policies.
Out of scope
- Applications our customers deploy on Tandem. Please report those to the site’s owner.
- Reports from automated scanners without a demonstrated, exploitable impact.
- Missing best-practice headers or settings with no security impact.