Security
Responsible disclosure for Newdrop (getnewdrop.com).
Report a vulnerability
Email security@getnewdrop.com (or support@getnewdrop.com). Please include:
- Description and impact
- Steps to reproduce (PoC welcome; no destructive testing)
- Affected URL / API / account type (anon, signed-in, admin)
Do notaccess or exfiltrate other customers' data, spam subscribers, or disrupt billing. We will acknowledge reports and remediate based on severity. Prefer email over support chat — do not paste exploit details into the AI helper.
Researchers: /.well-known/security.txt (RFC 9116).
Scope notes
- Intentional honeypot / decoy routes under
/api/v1/internal/*and related paths return canaries — hitting them is logged as abuse. - Card data is handled by Stripe; do not attempt to capture PANs on our origin.