Vulnerability Disclosure Policy

Effective date: September 15, 2026

We value the work of security researchers. This policy tells you how to report vulnerabilities in Diagrams.so, operated by RedHold LLC, safely. It is the policy referenced by our security.txt files. If you follow it in good faith, we will work with you to understand and fix the issue, and we will not pursue or support legal action against you for your research.

How to report

Email security@diagrams.so with:

  • a clear description of the issue and its impact;
  • step-by-step reproduction, including requests and responses (the X-Request-ID from any API response helps us trace it);
  • the affected URL, endpoint, or component, and any proof of concept;
  • your name or handle for acknowledgment, if you want one.

Please report promptly, give us reasonable time to fix the issue before any public disclosure, and keep the details confidential until we confirm a fix.

Scope

In scope:

  • diagrams.so and its subdomains, including api.diagrams.so;
  • the developer documentation at diagrams.so/developers;
  • the official MCP server (@diagrams-so/mcp) and SDKs (@diagrams-so/sdk on npm and diagrams-so on PyPI);
  • authentication, API key handling, billing and Credit metering, and tenant isolation.

Out of scope:

  • third-party services we use (Stripe, PropelAuth, AWS, our AI providers, analytics vendors): report those to the vendor;
  • findings that require stolen credentials, physical access, or a compromised device;
  • social engineering, physical attacks, and spam.

Rules of engagement

  • Test only against accounts and data you own. Note that test-mode keys consume your account's real Credit balance.
  • If you encounter another user's data or any personal data, stop immediately and report it. Do not access, download, alter, or keep it.
  • No denial-of-service, volumetric, or automated high-rate testing; do not degrade the service for others; do not destroy or alter data.
  • Use findings only for good-faith reporting, and do not disclose publicly before we confirm remediation.

What we do not consider a vulnerability

To keep signal high, we generally decline reports of the following unless they come with a concrete, exploitable impact: denial-of-service or rate-limiting observations; missing best-practice headers, cookie flags, or TLS configuration details; self-XSS, clickjacking on pages without sensitive actions, or missing email-authentication records on non-mail domains; raw automated-scanner output; version disclosure or verbose errors that leak no secrets; and reports that the AI produced an imperfect diagram, which is product feedback rather than a security issue.

Safe harbor

We consider security research conducted consistently with this policy to be authorized under the Computer Fraud and Abuse Act and similar state computer-misuse laws, including Virginia's, and we will not initiate or support legal action against you for accidental, good-faith violations of this policy. We waive claims under anti-circumvention law (DMCA section 1201) for research on our own systems within this policy's scope, and we waive restrictions in our Terms of Service and Acceptable Use Policy that would otherwise prohibit the research, for the limited purpose of following this policy. If a third party takes action against you for research that complied with this policy, we will make our authorization known. This safe harbor does not cover the third-party services listed as out of scope. If you are unsure whether something is covered, ask first.

What to expect from us

  • Acknowledgment of your report within 3 business days.
  • A severity assessment and, for valid reports, a remediation plan and timeline.
  • Credit on an acknowledgments page if you want it.
  • We do not operate a paid bug bounty and do not pay for reports; we may send thanks or swag at our discretion.

Coordinated disclosure

Please allow us a 90-day window to remediate before publishing, shorter by agreement for actively exploited issues, and coordinate timing with us. We will not take action against researchers who publish in good faith after the window lapses following genuine attempts to coordinate.

All policies