Security
Last updated: October 3, 2026
If you've found a security problem in Swebsy, we want to hear about it. Thank you for helping keep Swebsy and the people who use it safe.
Report a vulnerability
Email [email protected] with “Security” in the subject line. We'll reply within 3 business days.
What to include
- What you found and where: the URL, the feature, or the version of the MCP package
- Steps to reproduce it, plus screenshots or a short video if they help
- What an attacker could do with it
What happens next
We'll reply within 3 business days. We'll keep you updated while we fix it, and tell you when the fix is live. If you'd like credit, we're happy to thank you by name once it's fixed.
In scope
- swebsy.com and the Swebsy Studio editor
- api.swebsy.com
- Sites published on Swebsy Hosting, for problems in how we host them, not in a customer's own content
- The @swebsy/mcp package
Out of scope
- Denial-of-service or load testing
- Social engineering, phishing, or physical attacks
- Reports from automated scanners with no demonstrated impact
- Missing best-practice headers or settings that don't lead to a real exploit
Good-faith research
If you act in good faith, we won't take legal action against you. That means you:
- only access what you need to show the problem,
- don't keep, change, or share other people's data,
- give us reasonable time to fix it before you go public.
We don't run a paid bug bounty program at the moment.
How we protect your work
- Your projects stay on your device. The editor works locally in your browser and needs no account. Your sites only reach our servers if you turn on cloud sync or publish with Swebsy Hosting.
- Every upload is checked. Files go through our own authenticated API, which checks each file's size and integrity before storing it. Your browser never gets direct access to our storage.
- We never see your card. Payments go through Stripe.
- Admin access is locked down. Staff tools need a verified email and an admin role granted one account at a time.
- The site runs on HTTPS only, with strict security headers.
Contact
Security reports and questions go to [email protected]. Our machine-readable contact details are in security.txt.