Security at Alfred Wolf
We take the security of our software seriously. Despite every measure, vulnerabilities can exist. If you find one, we want to hear about it.
How to report
Send your report to security@alfredwolf.app. Please describe the vulnerability in as much detail as possible: what did you find, how can it be reproduced, and what impact does it have?
Our commitments
+We confirm receipt within 3 business days.
+We assess and fix the vulnerability as quickly as possible.
+We credit you by name (with your permission) in our acknowledgements.
+We take no legal action against anyone who follows this policy.
Our requests
–Do not exploit the vulnerability or access other people's data.
–Do not disclose the vulnerability publicly before we have fixed it.
–Do not perform denial-of-service attacks or spam.
Scope
·Alfred Wolf app (macOS, Windows)
·alfredwolf.app website
·Stripe billing API
·Seed server (Supabase Edge Functions)
Out of scope
–Third-party services (OpenAI, Anthropic, Ollama)
–General weaknesses without a concrete exploit