Security & Vulnerability Disclosure
The short version
Found a security issue? Email security@deky.app. We welcome good-faith research and won't pursue legal action for testing that follows this policy. We aim to acknowledge reports within three business days.
01Reporting a vulnerability
If you believe you've found a security vulnerability in Deky, please report it privately to security@deky.app. Include enough detail for us to reproduce the issue:
- What you found — the vulnerability type and its impact.
- Where — the affected URL, endpoint, or component (web app, recipient viewer, public API, or the Figma plugin).
- How to reproduce it — steps, a proof-of-concept, and any request/response details or screenshots.
Please give us a reasonable opportunity to fix the issue before disclosing it publicly, and don't access, modify, or delete data that isn't yours while testing.
02Scope
This policy covers the systems we operate:
- deky.app and the application (including the dashboard and authenticated APIs).
- The recipient viewer — tracked deck links (e.g.
/v/…and per-workspace share domains). - The public API —
/api/v1/…. - The Deky Figma plugin— "Deky — share this deck".
03Safe harbor
We consider security research and vulnerability disclosure conducted in good faith under this policy to be authorized. We will not pursue or support legal action against you for such research, provided you:
- make a good-faith effort to avoid privacy violations, data destruction, and interruption or degradation of our service;
- only interact with accounts you own or have explicit permission to access, and stop as soon as you've confirmed a vulnerability;
- don't exfiltrate data, and report promptly without exploiting the issue further or disclosing it publicly before it's fixed.
04What to expect
- Acknowledgement within three business days of your report.
- Triage & updates— we'll validate the issue, assess severity, and keep you informed of our progress.
- Remediation — we prioritize fixes by severity and address critical issues as quickly as we can.
05Out of scope
The following are generally out of scope. Reports limited to these will usually be closed without action:
- volumetric or denial-of-service attacks, automated scanner output without a demonstrated impact, and spam or social-engineering of our staff or users;
- missing best-practice headers, cookie flags, or rate limits with no concrete exploit; self-XSS; and clickjacking on pages with no sensitive action;
- issues in third-party services we rely on (e.g. Clerk, Cloudflare, Figma, Resend) — please report those to the respective vendor.
06Recognition
Deky does not currently run a paid bug-bounty program. We're grateful for responsible disclosure and are happy to publicly credit researchers who report valid issues, if you'd like. A machine-readable version of this policy is available at /.well-known/security.txt.
Questions about your data? privacy@deky.app — we reply within 30 days.