Security and reporting vulnerabilities
If you spot something wrong, we would rather hear it from you than from somebody else. Below is how to report it, what is in scope and what you get back from us.
Last updated: 1 October 20261How to report
Mail [email protected]. A person reads that address. Tell us what you found, on which URL or in which app, and how to reproduce it. A short clip or a couple of screenshots help more than a forty-page scanner report.
You can encrypt sensitive details with our PGP key. You do not have to: an unencrypted report beats no report.
- Within three working days an acknowledgement from a person, not an autoresponder.
- Within ten working days you hear whether we accept it, what we think the impact is and when we will fix it.
- Once it is fixed, you hear so and you are free to publish.
We ask you to wait 90 days before publishing, or less when we are done sooner. If it takes longer, we tell you why.
PartyPPL is a small platform without a security department. We do not pay a bug bounty. What we do: answer quickly, be honest about what we will and will not fix, and credit you by name if you want that.
2What is in scope
Everything on partyppl.nl and its subdomains, and the short address pppl.app: the site, the organiser portal, the API under /api/v1 and the MCP server, the ticket flow, the Apple Wallet service, pairing an Apple TV, the widget and Live Activity feeds, the mail we send, and the apps for iPhone, iPad, Apple Watch, Mac and Apple TV.
- Access to another account's data: tickets, chats, e-mail addresses, dates of birth, widget data.
- Bypassing login, the 18+ check or the roles in the organiser portal.
- Injection into the database, the page or the search index.
- Faults in the payment or ticket flow that get you a ticket without paying, or somebody else's ticket; also through resale, transfer or a Wallet pass.
- Reading or altering other people's uploads, or getting into organisations' shielded storage.
- Hanging an Apple TV or API token on someone else's account.
Out of scope: a bare scanner report, missing headers without a working exploit, TLS settings of our CDN provider, self-XSS, social engineering, and third-party services such as Stripe, Resend, Cloudflare, Apple or Anthropic. Take those to them.
3Ground rules for testing
Test on your own account and your own data only. If you reach somebody else's data, stop right there, keep nothing, and say in your report how much you saw.
- No automated scans against login, payment and tickets. Those hit real visitors at the door.
- No denial of service, no load tests, no spamming our mail sender or push notifications.
- No charging back real payments, no scanning or reselling other people's tickets.
- Do not download, keep or share other people's data, and do not change or delete anything that is not yours.
- Leave no back door and do not keep access once you have shown that you could.
Stay within this and we treat your research as good faith and will not take legal action. We cannot promise that on behalf of our suppliers.
4Acknowledgments
Everyone who reports a vulnerability we confirm and fix is listed here, under the name or handle you pick, with the month and one line about what it was. Anonymous is fine too.
Nobody yet. No report has been confirmed so far. This list is empty because it is honest, not because it was forgotten.
5Working on security at PartyPPL
There is no vacancy open right now. If one comes up, it will be here.
Want to help build? Mail [email protected] with what you are good at. We are looking for people who can run a pentest and explain it rather than people who forward a report.
6PGP key
Encrypt sensitive details with this key. Check the fingerprint before you use it.
- Fingerprint
- E5D2 6476 4523 7FA9 9C0C A348 34DE 15CF CFE7 5F58
- Belongs to
- [email protected] and [email protected]
- Type
- Curve25519 (EdDSA), created 17 September 2026, no expiry
The machine-readable policy is at /.well-known/security.txt.
What changed
- The scope now also names the apps, the MCP server, Apple Wallet, pairing an Apple TV, the widget feeds and pppl.app.
- Ground rules extended for payments, resale and push notifications.