Responsible disclosure

Security.

KindlyDue reduces risk by keeping the current invoice draft in the browser. The separate paid account boundary stores only identity and purchase state. It uses one-way password hashes, verified-email activation, revocable secure cookie sessions, login lockouts, and Cloudflare rate limits. Purchase records are available only through the server Worker, and access is granted only after Stripe's signed confirmation passes exact product and price checks.

Report a vulnerability

Send reports to security@kindlydue.com. Include reproduction steps, impact, affected URL or version, and any suggested mitigation. Do not include real client or invoice information in a report.

Safe-harbor intent

Good-faith research that avoids privacy violations, service disruption, social engineering, and data destruction will be acknowledged and investigated. The response target is an initial acknowledgment within two business days and a severity or next-step update within five.