MAKEIY is built for people who find vulnerabilities for a living. If you find one in MAKEIY itself, we want to hear about it.
Email support@makeiy.com with the affected URL or endpoint, the steps to reproduce, and what you were able to access or change. Please give us a reasonable window to respond before disclosing publicly.
Test only against your own MAKEIY account. Do not attempt to access other users' data, run denial-of-service or volumetric tests, use automated scanners against our infrastructure, or social-engineer our team or users.
Passwords are stored only as bcrypt hashes, never in plaintext or a reversible form. Sessions use signed tokens with the algorithm pinned on verification, and authentication endpoints are rate limited per IP.
Reset links are single-use and expire 30 minutes after they are issued. Only a hash of the token is stored, so the link in your inbox cannot be reconstructed from our database, and repeated failed attempts lock the link.
MAKEIY runs reconnaissance and scanning tools on your behalf. You are responsible for having explicit authorisation for every target you point it at — a bug bounty program scope, a written engagement, or infrastructure you own. See About MAKEIY for the full ethical-use position.