Security Policy
Version: 1.0
Effective: September 1, 2026
We welcome security research. If you have found a vulnerability in our website, in a Cloud Service we operate, or in the source code we publish, report it through the process below. This policy describes what researchers acting in good faith can expect from us and the boundaries of authorized testing.
This is the policy that Section 16 of our Terms of Service (dependably.ca/terms) refers to. It defines the scope of authorized testing and our safe harbour, and it is incorporated into those Terms for researchers who follow it. Testing outside this policy is not authorized (Terms Section 4; Acceptable Use Policy Section 3, dependably.ca/aup).
This policy covers vulnerability reports. To report abuse of our services, such as malicious content or a compromised account, follow Section 8 of the Acceptable Use Policy; security-relevant abuse also goes to security@dependably.ca.
1. Scope
1.1 In scope
dependably.caand the subdomains we operate (the Site, as the Terms define it)- Dependably Cloud and the hosted plans for Dependably StatusCheck (the Cloud Services, as the Terms define them)
- The source code we publish, in the repositories we operate
- Authentication, authorization, and access control in any of the above
1.2 Out of scope
- Self-hosted deployments of Dependably Packages or Dependably StatusCheck run by someone else. A vulnerability in the code itself belongs to us and is in scope; the operator's infrastructure, configuration, and data are governed by the operator's own disclosure program. Do not test an operator's deployment without that operator's permission.
- Third-party services and software we use but do not develop, such as our hosting and DNS providers. Report those to the vendor.
- Social engineering of anyone at MoonlitLabs Computing Ltd. or of our customers
- Physical attacks against people or premises
- Denial-of-service testing. Do not run load or stress tests against the Site or any service we operate.
- Spam-related findings (open SMTP relay, missing SPF or DMARC records) unless they enable a credible spoofing attack
- Best-practice findings without a demonstrated impact, such as a missing security header on a static page with no sensitive content
We cannot authorize testing of systems we do not control. The safe harbour below applies only to assets in scope.
2. How to report
Email security@dependably.ca with:
- Affected component: URL, endpoint, repository and file, or feature
- Steps to reproduce, clear enough that we can replicate the issue
- Impact: what the vulnerability allows an attacker to do
- Suggested severity: your assessment (Critical, High, Medium, Low)
- Whether you have shared this with anyone else, including AI services
- How you would like to be credited, or not, once the issue is fixed
If your report contains sensitive material, such as working exploit code or screenshots of real data, say so in your first email before you send it.
We do not pay bug bounties. With your consent, we credit researchers publicly once the fix ships.
3. What to expect from us
These are targets, not contractual commitments.
| What | Target |
|---|---|
| Acknowledge your report | Within 2 business days |
| Initial triage: validate severity, scope, reproducibility | Within 5 business days |
| Substantive update | At least every 14 days while the report is open |
| Fix, Critical | Within 30 days |
| Fix, High | Within 60 days |
| Fix, Medium and Low | Best effort, prioritized in the normal backlog |
| Coordinated disclosure | We work with you on a public disclosure date once a fix is in place |
If we miss a target, we will tell you why and propose a revised timeline.
4. Safe harbour
If you act in good faith under this policy, MoonlitLabs Computing Ltd. will not pursue legal action against you for the activity described in your report. Specifically:
- We will not initiate civil action against you, or refer you to law enforcement, for security research consistent with this policy.
- We will not bring or support a claim or complaint under the Criminal Code (Canada, section 342.1, unauthorized use of a computer), the Computer Fraud and Abuse Act (United States), the Computer Misuse Act (United Kingdom), or equivalent laws in your jurisdiction, for research consistent with this policy.
- If a third party initiates legal action against you for research consistent with this policy, we will make clear to that party that the activity was authorized.
- We will not seek damages for incidental data access that was necessary to validate a vulnerability, provided you minimized the access, did not retain or share the data, and notified us promptly.
If you are unsure whether something you plan to do is consistent with this policy, stop and ask us at security@dependably.ca before continuing.
4.1 To stay within safe harbour, you must
- Make a good-faith effort to avoid harm. No data exfiltration beyond what is needed to demonstrate the issue, no service disruption, no attacks against resources belonging to a specific customer or user without their permission.
- Keep automated scanning to a low request rate. Do not run load or stress tests.
- Stop testing and notify us promptly once you confirm a vulnerability.
- Do not publish details until we have shipped a fix and agreed on a disclosure date with you, or 90 days after your report, whichever comes first.
- Do not access, modify, or delete other people's data. If you encounter customer or user data by accident: stop, do not retain it, and tell us.
- Do not use the vulnerability to harm third parties, demand payment, or for any purpose other than reporting it to us.
- Do not violate any other law. Safe harbour covers research, not unrelated criminal activity.
4.2 What is outside safe harbour
- Attacks against a specific customer's tenant or data, or against third parties, using anything in scope
- Attacks against people at MoonlitLabs Computing Ltd. or their premises
- Testing of systems outside the scope above, including operator-run self-hosted deployments and the third-party services we use
- Sharing the details of a finding with third parties, including AI services that retain or train on their inputs, before disclosure is agreed
- Sale or extortion of the vulnerability
- Public disclosure before the agreed date, or before the 90 days in Section 4.1, without coordination
5. Recognition
With your consent, we credit confirmed researchers on this page after the fix ships. We will ask what form you would like: name, handle, organization, or anonymous.
6. Questions or feedback
Dependably Packages and Dependably StatusCheck are products of MoonlitLabs Computing Ltd., a Canadian company.