Across Chubby Club
Security & Disclosure
Security practices, reporting and research boundaries.
Draft — pending review. This shared edition has not taken effect and does not replace existing notices or agreements.
On this page
1. Security across the Services
Chubby Club uses administrative and technical measures appropriate to the Service and information involved. These include access restrictions, secure communications, logging and incident review. No internet service guarantees absolute security. This document does not claim an independent audit or security certification across the platform.
2. Report a concern
For this Legal site, contact security@chubbyclub.com. For Partner, use legal@chubbyclub.com. For another Service, consult its /.well-known/security.txt and published contact. Admin’s terms ask users to report suspected credential compromise to privacy@chubbyclub.com.
Include the affected URL or feature, safe reproduction steps, likely impact and a contact method. Do not send passwords, tokens, keys, tax identifiers or other people’s personal information.
3. Partner safeguards and research terms
The following provisions apply specifically to the partner portal. Their safe harbor is not an authorization to test unrelated Services or third-party systems.
1. Security practices
Current safeguards in the application include:
- Sign-in using the OAuth authorization-code flow with PKCE.
- Sessions maintained with signed, secure, HTTP-only cookies with limited lifetimes.
- Role and partner-scope verification for staff and portal access.
- Access-controlled storage for private partner reports.
- Authenticated agreement-provider events retained for auditing.
- Server logging designed to exclude passwords, credentials, and personal-information payloads.
These practices describe the current application design. They are not a representation that the service holds a particular security certification or has completed an independent compliance audit.
3. Responsible research and safe harbor
We support good-faith security research. If you research and report a vulnerability in accordance with this page, we will not initiate or recommend legal action against you for that research. To stay within this safe harbor:
- Do not access, copy, or exfiltrate data that does not belong to you. If you encounter information that is not yours, stop testing and report the concern immediately.
- Do not disrupt the service, degrade it with automated traffic, or destroy or alter data.
- Do not use social engineering, phishing, or physical attacks against Chubby Club, its partners, or its personnel.
- Do not violate the privacy of members, partners, or staff.
- Give us a reasonable time to remediate the issue before any public disclosure, and coordinate disclosure timing with us.
4. What to expect from us
We review reports in good faith, may ask for additional technical detail, and will coordinate remediation and disclosure with you when appropriate. This page does not create a bug bounty program, promise payment, or authorize activity that would otherwise be unlawful or outside the boundaries described above.
4. Privacy requests and updates
To request access, correction or deletion, use Data Requests & Deletion. Reported security issues are assessed and remediated, with notification as applicable law requires. A uniform research policy for all Services remains a policy-owner decision; existing scope-specific permissions are preserved.