Security acknowledgments
BabyGrade welcomes coordinated security disclosure. If you find a vulnerability, email security@babygrade.net. We aim to acknowledge within 72 hours and fix or remediate critical issues within 30 days.
Scope
- babygrade.net (and subdomains)
- The BabyGrade iOS and Android applications when released
- Any Firebase Cloud Function under the baby-food-scanner project
Out of scope
- Social engineering of staff or contractors
- Denial-of-service or volumetric testing
- Findings against third-party services (Vercel, Firebase, Stripe, RevenueCat) outside our configuration
- Reports generated solely by automated scanners with no proof of exploitability
Hall of recognition
No external researcher reports yet. This page will list researchers who have responsibly disclosed vulnerabilities, with their consent.