Skip to content
SQUADJET.
How it works Pricing About Account Log in Price a trip
SQUADJET.
Price a trip How it works Pricing About Account Log in

SquadJet - group flight meetup planning

§ / Security

Found a hole? Tell us first.

Effective 2026-07-19 · Contact security@squadjet.io

01 / How to report 02 / Safe harbor 03 / Scope 04 / Rules of engagement 05 / Out of scope 06 / Coordinated disclosure 07 / Where your data lives

01 / How to report

Email us, with enough to reproduce it.

Found a security issue in SquadJet? Email security@squadjet.io. This is the same address published in our security.txt (RFC 9116).

Please include what we need to confirm and fix it:

  • The affected URL, page, or API endpoint.
  • Clear steps to reproduce - a short proof of concept beats a scanner dump.
  • The impact you believe it has, and any prerequisites.

We acknowledge reports within 3 business days and aim to keep you updated as we triage and fix. There is no cash bounty program today, but we credit reporters who want it once an issue is resolved.

02 / Safe harbor

Good-faith research is welcome.

If you make a good-faith effort to follow this policy, we will treat your research as authorized, we will not pursue or support legal action against you for it, and we will work with you to understand and resolve the issue quickly. If a third party brings legal action against you for activity that complied with this policy, we will make that authorization known.

Our authorization covers only the systems SquadJet controls. We cannot authorize testing of our third-party providers (for example Stripe, Amazon, or our search-data provider); their own security programs govern any testing of their systems.

This safe harbor covers your testing, not your conduct afterward: accessing more data than needed to demonstrate an issue, disrupting the service, or disclosing publicly before we have fixed it falls outside it.

03 / Scope

The site and its API.

In scope: squadjet.io, the subdomains we operate, and the SquadJet API. Findings in our own code and configuration are what we can act on.

Our authorization covers only the systems SquadJet controls. We cannot authorize testing of our third-party providers (for example Stripe, Amazon, or our search-data provider); their own security programs govern any testing of their systems. If you find a way our integration exposes user data or funds, that is in scope - report it here. The full list of who processes what is in section 07.

04 / Rules of engagement

Test carefully. Respect other people.

  • Use only test accounts you control. Do not access, modify, or delete data that is not yours.
  • Stop at proof of concept - take only the minimum needed to demonstrate the issue.
  • No denial-of-service, volumetric, or load testing, and no automated scanning that degrades the service for others.
  • No social engineering, phishing, or physical attacks against our staff, users, or vendors.
  • Keep what you find confidential until we have shipped a fix (see 06).

05 / Out of scope

Reports we usually can't action.

These are generally not accepted on their own, absent a concrete, demonstrated impact:

  • Missing best-practice headers or cookie flags with no working exploit.
  • Self-XSS, or issues that need a fully compromised device or browser.
  • Rate-limiting or brute-force concerns without a demonstrated bypass.
  • Reports produced only by an automated scanner, with no verified impact.
  • Findings in third-party platforms (Stripe, Amazon) that do not stem from our integration.

06 / Coordinated disclosure

Give us time to fix it first.

Please give us a reasonable window to remediate before disclosing publicly - 90 days is our default, and we are happy to coordinate a timeline and credit you when we announce the fix. We will keep you posted on progress and let you know when the issue is resolved.

07 / Where your data lives

Our subprocessors.

The third parties that host or process SquadJet data - AWS, Stripe, and our search-data provider - are listed, with the job each one does, in the subprocessor list on our privacy page. That list is the maintained source of truth for who touches what.

SquadJet © 2026 - Group flight meetup planning

About FAQ Support Privacy Terms Refunds Security

SQUADJET