Security & Responsible Disclosure

Last updated: April 2026

We take security personally.

TinyX is built by security-aware folks. This isn't a side project that happens to have encryption — security is the product. Our infrastructure runs on Cloudflare Workers with zero-knowledge encryption, and we treat every vulnerability report like it's our own systems on the line. Because it is.

Reporting a vulnerability

Found something? Don't sit on it. Email security@tinyx.co with:

Use our security.txt for PGP-encrypted communication if you prefer.

What we promise

Scope — what's in

Scope — what's out

Bug bounty

We don't run a formal bounty programme with fixed payouts. But we do reward good-faith researchers who find real issues. The form varies — sometimes it's cash, sometimes it's a lifetime Pro/Max account, sometimes it's a public shoutout and a reference. It depends on severity and impact.

What we can guarantee: if you find something real and report it responsibly, we won't ignore you, and we won't be cheap about it.

Rules of engagement

Want a playground?

Yes, we have a dedicated test environment for security researchers. Same codebase, same infrastructure, same Cloudflare stack — connected to Stripe Sandboxes so no real money moves. Be nice and ask for access at security@tinyx.co. We'll get you set up.

A few ground rules for the playground:

Our security stack

Questions? security@tinyx.co. No forms. No chatbots. Just email.

Back to home