Security

If you have found a security vulnerability in CONSTRUKTR, we want to hear about it directly, before it becomes a problem for the contractors who trust us with their business.

Reporting a vulnerability

Email support@construktr.ai with a description of the issue, the steps to reproduce it, and any proof-of-concept material. Please report privately by email rather than a public issue or social post, so we can investigate and fix a real problem before it is disclosed.

We will acknowledge your report, investigate it, and work with you to verify and fix confirmed vulnerabilities. We do not currently run a paid bug bounty program.

What we ask

  • Give us a reasonable amount of time to investigate and fix an issue before any public disclosure.
  • Avoid accessing, modifying, or deleting data that is not yours, beyond what is necessary to demonstrate the issue.
  • Do not run automated scanning or load testing against production without contacting us first.
  • Act in good faith and avoid privacy violations, service disruption, or degraded experience for other users.

Good-faith security research conducted under this policy is authorized, and we will not pursue legal action against a researcher who follows it.

Machine-readable contact

This policy is also published at /.well-known/security.txt in the RFC 9116 format that security tools and researchers look for automatically.

For anything else, including account or billing questions, use our support page.