Security
Last updated: August 3, 2026
If you believe you have found a security vulnerability in Updog, we want to hear about it. This page explains how to report it, what we commit to, and what is in scope.
A machine-readable version of this policy is available at /.well-known/security.txt.
1. How to report
Email [email protected]. Include enough detail for us to reproduce the issue: the affected URL or package version, the steps you took, and what you observed.
Do not include personal data belonging to other people in your report. If a proof of concept needs data, use data you created yourself.
2. What we commit to
We will acknowledge your report by email within 5 business days of receiving it.
We do not commit to a remediation timeline. We are a small team and we fix issues in order of severity.
3. In scope
Our web properties:
updog.techand its subdomains, includingconsole.updog.tech,api.updog.tech, anddemo.updog.tech.
The @updog/data-editor and @updog/data-editor-wc packages published on npm, in particular:
- Cross-site scripting via data rendered inside the editor grid, cells, dropdowns, or modal chrome.
- License-validation bypass.
- Memory corruption or unsafe behavior in file parsing, in any supported format: CSV, TSV, JSON, XML, XLSX, XLS, XLSB, ODS.
- Any vulnerability that lets a user of the host page access data or functionality they should not.
We support only the most recent minor version of each package. Older versions are not patched.
4. Out of scope
- Applications built by our customers. If you find an issue in a site that embeds the Updog SDK, report it to the owner of that site, not to us. Do not test against it.
- Denial of service, load testing, and traffic flooding, including exhausting the browser with an arbitrarily large input file.
- Social engineering of our team, our customers, or our service providers.
- Automated scanner output submitted without demonstrated impact. Missing headers, cipher preferences, and version disclosure are not vulnerabilities on their own.
- Issues that require a compromised npm registry, CDN, or customer API key to exploit.
- Issues in third-party services we use. Report those to the service concerned.
5. Safe harbor
If you act in good faith, stay within the scope above, and give us a reasonable opportunity to respond before disclosing publicly, we will not initiate legal action against you and will not ask anyone else to do so on our behalf.
This does not cover actions that harm our users or our customers, including accessing data that is not yours, degrading the service, or withholding a finding in exchange for payment.
6. Rewards
We do not operate a bug bounty program and we do not pay for reports.
7. Contact
Updog Software Solutions FZCO
Security reports: [email protected]
All other inquiries: [email protected]