Security contact
Last updated: September 29, 2026
This page is the security contact for VietLing, vietling.com, and the VietLing backend. It lists where reports go, what to include, and what to expect.
Report a security problem
Security reports go through GitHub private vulnerability reporting on the VietLing repository: github.com/vietling/vietling-releases/security/advisories. Private reports are visible only to the maintainers - do not file them as public issues.
The VietLing repository is private during the pre-release period, so that channel opens with the public launch. Until then, VietLing is not distributed and there is no build on your device to report against. Concerns about this site or your VietLing Account go through the support page.
What to include
- The affected component: vietling.com, api.vietling.com, github.com/vietling/vietling-releases, or the VietLing app.
- Steps to reproduce, and what an attacker could do with the issue.
- Proof-of-concept material where you have it - screenshots, requests, or a minimal script.
Scope
- In scope: vietling.com, api.vietling.com, github.com/vietling/vietling-releases, and the VietLing app itself.
- Out of scope: our vendors - Clerk (login), Paddle (payments), Cloudflare (hosting) - which run their own disclosure programs.
- Denial-of-service findings are accepted only against the VietLing backend, not vendor infrastructure.
What to expect
- Reports are acknowledged when the team reviews them; no response SLA is published during the pre-release period.
- Coordination, fixes, and any disclosure happen inside the private report thread.
- VietLing does not run a bug bounty program and does not pay for reports.