Report a security issue.
UPDATED 2026-08-01Email privacy@ladle.chat with the details. If the issue is sensitive, PGP is available at ladle.chat/pgp (fingerprint in the header of that page). We acknowledge receipt within one business day.
For vulnerabilities in the LADLE product: please practice coordinated disclosure. Give us a reasonable window (typically 30-90 days depending on severity) to remediate before public disclosure. We will engage in good faith and will not use legal threats against researchers acting in good faith.
We currently do not operate a paid bug bounty. As a small team on a subscription revenue model, we can't sustain the operational overhead of a formal bounty program with a triage queue and payout infrastructure. We can offer public acknowledgment on a security page (with permission), swag, and a genuine thank-you. If you'd rather donate the equivalent to WFP directly, we can facilitate that.
We do not consider the following in scope: theoretical attacks that require physical access to a user's unlocked device, social engineering of our subscribers or our team, DoS via traffic flooding, or issues in Anthropic's underlying API (report those to Anthropic directly at their security-reporting page).
We DO consider in scope: authentication and session bugs, IDOR (accessing other users' data), XSS or CSRF, misconfigurations that expose data to third parties, privilege escalation, and any bug that would let a subscriber see another subscriber's chat history or meal ledger.
If the issue is critical and requires immediate action (active exploitation observed), mark the email with [URGENT-SECURITY] in the subject line and we escalate immediately.