Updog
FeaturesPricingFAQ
DocsChangelogStatus
FrameworksCompareBlog
Sign up
FeaturesPricingFAQDocsChangelogStatusFrameworksCompareBlog

Security

Last updated: August 3, 2026

If you believe you have found a security vulnerability in Updog, we want to hear about it. This page explains how to report it, what we commit to, and what is in scope.

A machine-readable version of this policy is available at /.well-known/security.txt.

1. How to report

Email [email protected]. Include enough detail for us to reproduce the issue: the affected URL or package version, the steps you took, and what you observed.

Do not include personal data belonging to other people in your report. If a proof of concept needs data, use data you created yourself.

2. What we commit to

We will acknowledge your report by email within 5 business days of receiving it.

We do not commit to a remediation timeline. We are a small team and we fix issues in order of severity.

3. In scope

Our web properties:

  • updog.tech and its subdomains, including console.updog.tech, api.updog.tech, and demo.updog.tech.

The @updog/data-editor and @updog/data-editor-wc packages published on npm, in particular:

  • Cross-site scripting via data rendered inside the editor grid, cells, dropdowns, or modal chrome.
  • License-validation bypass.
  • Memory corruption or unsafe behavior in file parsing, in any supported format: CSV, TSV, JSON, XML, XLSX, XLS, XLSB, ODS.
  • Any vulnerability that lets a user of the host page access data or functionality they should not.

We support only the most recent minor version of each package. Older versions are not patched.

4. Out of scope

  • Applications built by our customers. If you find an issue in a site that embeds the Updog SDK, report it to the owner of that site, not to us. Do not test against it.
  • Denial of service, load testing, and traffic flooding, including exhausting the browser with an arbitrarily large input file.
  • Social engineering of our team, our customers, or our service providers.
  • Automated scanner output submitted without demonstrated impact. Missing headers, cipher preferences, and version disclosure are not vulnerabilities on their own.
  • Issues that require a compromised npm registry, CDN, or customer API key to exploit.
  • Issues in third-party services we use. Report those to the service concerned.

5. Safe harbor

If you act in good faith, stay within the scope above, and give us a reasonable opportunity to respond before disclosing publicly, we will not initiate legal action against you and will not ask anyone else to do so on our behalf.

This does not cover actions that harm our users or our customers, including accessing data that is not yours, degrading the service, or withholding a finding in exchange for payment.

6. Rewards

We do not operate a bug bounty program and we do not pay for reports.

7. Contact

Updog Software Solutions FZCO
Security reports: [email protected]
All other inquiries: [email protected]

Updog

Client-side CSV importer and spreadsheet editor with a first-class React package and a Web Component for every other frontend framework.

@updog/data-editor on npm@updog/data-editor-wc on npm

Product

FeaturesPricingFAQFrameworksCompare

Developers

DocumentationChangelogStatus

Company

AboutBlog

Legal

Privacy PolicyTerms of ServiceCookie PolicyCookie SettingsSDK LicenseSecurity

© Updog Software Solutions FZCO. All rights reserved.