Found a vulnerability? Please tell us. Email security@greeksview.com. We read every report, we will acknowledge you within three business days, and we will not pursue legal action against anyone who reports in good faith under the guidelines below.
Send us enough to reproduce the issue: the affected URL or endpoint, the steps you took, and what you observed. A proof of concept helps. If a report contains sensitive detail, say so and we will arrange another channel.
Please give us a reasonable window to ship a fix before disclosing publicly. We will tell you when the fix is live, and we are happy to credit you unless you would rather stay anonymous.
/api/ or /admin routeSome context that may save you time. Broker and AI credentials are encrypted client-side with a key
that cannot be exported from the browser, so they are never transmitted to or stored on our servers.
Session cookies are httpOnly and, in production, carry the __Host- prefix. The admin console
uses entirely separate credentials with mandatory two-factor authentication, server-side sessions, and an
append-only audit trail. Passwords are hashed with bcrypt, and email tokens are stored only as SHA-256
hashes.
We are a small independent product and do not run a paid bug-bounty programme. We will acknowledge valid reports here and credit you by name or handle if you would like.
security@greeksview.com · machine-readable version at /.well-known/security.txt
Fathomline Analytics LLC · 4601 E. Douglas Ave., Ste 150, Wichita, KS 67218