Skip to content

Security

Responsible disclosure for Newdrop (getnewdrop.com).

Report a vulnerability

Email security@getnewdrop.com (or support@getnewdrop.com). Please include:

  • Description and impact
  • Steps to reproduce (PoC welcome; no destructive testing)
  • Affected URL / API / account type (anon, signed-in, admin)

Do notaccess or exfiltrate other customers' data, spam subscribers, or disrupt billing. We will acknowledge reports and remediate based on severity. Prefer email over support chat — do not paste exploit details into the AI helper.

Researchers: /.well-known/security.txt (RFC 9116).

Scope notes

  • Intentional honeypot / decoy routes under /api/v1/internal/* and related paths return canaries — hitting them is logged as abuse.
  • Card data is handled by Stripe; do not attempt to capture PANs on our origin.