Security
Vulnerability disclosure · security@keepingup.com
How we protect your data
- TLS 1.3 encryption for all data in transit
- Bank credentials never stored — Plaid handles all credential storage with bank-level security
- Database access restricted by role-based permissions; production data is not accessible in development
- Authentication via Clerk with rate limiting and brute-force protection
- Regular dependency audits via automated tooling
- All API routes require authentication; no unauthenticated access to user data
Vulnerability Disclosure Policy
If you discover a security vulnerability in Keeping Up, we ask that you report it to us responsibly so we can address it before it is publicly disclosed. We are committed to working with security researchers in good faith.
How to Report
Email your findings to security@keepingup.com. Please include:
- A description of the vulnerability and its potential impact
- Steps to reproduce the issue (proof of concept if available)
- Any relevant screenshots, logs, or payloads
- Your contact information for follow-up
PGP key available on request for sensitive disclosures.
Our Commitments
- We will acknowledge receipt of your report within 2 business days
- We will provide an estimated timeline for remediation within 5 business days
- We will notify you when the vulnerability is resolved
- We will not pursue legal action against researchers acting in good faith under this policy
- We will credit you in our security acknowledgements (if you wish)
Scope
In scope: keepingup.com, www.keepingup.com, and all subdomains. API endpoints at keepingup.com/api/*.
Out of scope: Third-party services (Plaid, Stripe, Clerk, Vercel) — please report those to the respective vendors. Denial of service attacks. Social engineering of our team.
Responsible Disclosure Guidelines
- Do not access or modify data belonging to other users
- Do not perform testing that degrades service availability
- Do not disclose the vulnerability publicly until we have had a reasonable opportunity to address it (90 days)
- Comply with all applicable laws
Bug Bounty
We do not currently offer a formal bug bounty programme. We are happy to acknowledge your contribution publicly and may offer a Pro subscription as a goodwill gesture for significant findings, at our discretion.