Security & Responsible Disclosure

If you believe you have found a security vulnerability in Itch Tickets, we want to hear about it.

How to report

Email akiva@itchtix.com with the subject line "Security report". Include:

  • A clear description of the issue and its impact.
  • Steps to reproduce, including any proof-of-concept code or screenshots.
  • The affected URL(s) and the date/time you observed the issue.

We acknowledge reports within 2 business days and aim to triage within 5 business days.

Our commitments

  • We will not pursue legal action against researchers who act in good faith and follow this policy.
  • We will keep you informed of progress and coordinate disclosure timing.
  • We will publicly credit researchers (with permission) for valid reports.

Out of scope

  • Volumetric DoS or stress testing.
  • Social engineering of staff, sellers, or customers.
  • Reports based purely on missing security headers without demonstrable impact.
  • Vulnerabilities in third-party services we depend on (please report directly to them).

Machine-readable contact info is published at /.well-known/security.txt.