Boonwerks

Security

Security reports are reviewed by the people operating Boonwerks products. Please report suspected account compromise, unauthorized access, sensitive-data exposure, or a reproducible product vulnerability privately.

Report a concern

Email team@boonwerks.com with “Security” in the subject. Include the affected product, the smallest reproducible set of steps, potential impact, and a safe way to contact you. Do not include passwords, access tokens, private user data, or destructive proof.

What to expect

We prioritize active account compromise, exposed credentials, and vulnerabilities that could affect user privacy. We will acknowledge actionable reports as soon as practical and coordinate before any public disclosure. Boonwerks does not currently operate a paid bug-bounty program.

Scope

Public Boonwerks websites, partner services, and the OnlyRun services operated by Boonwerks are in scope. Social engineering, denial-of-service testing, spam, automated credential attacks, and testing against other users are not authorized.