Security & Responsible Disclosure
If you believe you have found a security vulnerability in Itch Tickets, we want to hear about it.
How to report
Email akiva@itchtix.com with the subject line "Security report". Include:
- A clear description of the issue and its impact.
- Steps to reproduce, including any proof-of-concept code or screenshots.
- The affected URL(s) and the date/time you observed the issue.
We acknowledge reports within 2 business days and aim to triage within 5 business days.
Our commitments
- We will not pursue legal action against researchers who act in good faith and follow this policy.
- We will keep you informed of progress and coordinate disclosure timing.
- We will publicly credit researchers (with permission) for valid reports.
Out of scope
- Volumetric DoS or stress testing.
- Social engineering of staff, sellers, or customers.
- Reports based purely on missing security headers without demonstrable impact.
- Vulnerabilities in third-party services we depend on (please report directly to them).
Machine-readable contact info is published at /.well-known/security.txt.