Security Policy
Blocks takes the security of our platform and our customers seriously. If you find a vulnerability, we want to hear from you.
Scope
In scope:
- blocks.cloud and its subdomains
- The Blocks platform and Major Tom
- Blocks public APIs
Out of scope:
- Any customer AWS account or customer infrastructure. Never test these, even if you find a path to them. Report the path instead.
- Third-party services we use (report to the vendor)
- Denial of service, social engineering, phishing, and physical attacks
Rules
- Only use accounts you created yourself.
- If you access customer data, stop. Do not download, keep, or share it. Report immediately.
- Show impact with the minimum access needed. A proof of concept is enough.
- Give us reasonable time to fix the issue before you disclose it.
How to report
Email security@blocks.cloud with:
- The affected URL or endpoint
- Steps to reproduce
- The impact you observed
- How we can reach you
What happens next
- We confirm receipt within 3 business days.
- We triage and share our assessment within 10 business days.
- We update you at least every 30 days until the issue is fixed.
- We ask that you wait 90 days from your report, or until we release a fix, before publishing.
Safe harbor
If you act in good faith and follow this policy, we will not take legal action against you for your research. If a third party takes action against you over research that followed this policy, we will make it known that you acted with our authorization.
Rewards
We do not run a paid bug bounty. With your permission, we will credit you publicly once the issue is fixed.
Reports we will not act on
Unless you show real impact, we will close reports about:
- Missing SPF, DKIM, or DMARC records
- Missing security headers
- Clickjacking on pages without sensitive actions
- Self-XSS
- Software version disclosure
- Missing rate limits on non-sensitive endpoints
- Unverified output from automated scanners
Last updated: September 2026