Coordinated Disclosure of Security Vulnerabilities
We want to keep Ubikas safe for everyone on campus. If you have discovered a security vulnerability in Ubikas, we appreciate your help in disclosing it to us in a coordinated manner.
Effective July 30, 2026
Reporting a Vulnerability
Email security@ubikas.app with enough detail for us to reproduce the issue — the affected endpoint or screen, the steps you took, and what you saw. Proof-of-concept code and screenshots help. Our contact details are also published at /.well-known/security.txt.
If the report contains sensitive detail, say so and we will arrange an encrypted channel before you send it.
Legal Safe Harbor
We will not pursue legal action against researchers who report vulnerabilities in good faith and in accordance with this policy. If a third party brings a claim against you for research that followed this policy, we will make it known that your actions were authorized.
This protection applies as long as you stay inside the scope below and follow what we ask. Testing that goes beyond it is not authorized, and we cannot offer safe harbor for it.
Scope
In scope:
- the Ubikas mobile app for iOS and Android
- ubikas.app and Ubikas-owned subdomains, including the API and the operations dashboard
Out of scope:
- the infrastructure of our providers — reports about them belong to their own disclosure programs, not ours
- the systems, networks and websites of the institutions that deploy Ubikas
- findings that require a rooted or jailbroken device, a physically compromised device, or an outdated app version
- reports produced only by an automated scanner, with no demonstrated impact
- missing security headers, weak TLS ciphers, or similar configuration findings with no working exploit path
- denial of service, volumetric testing, spam, and social engineering
What We Ask
- Give us a reasonable opportunity to fix the issue before you disclose it publicly. We will agree a timeline with you.
- Do not access, modify or delete data belonging to other people. Use your own test account. If you come across someone else's data, stop, and tell us what you saw.
- Do not degrade Ubikas for the people using it. No denial-of-service testing, no automated scanning that generates significant load, no spam.
- Do not use social engineering against our team, our users, or the institutions we work with.
- Stay within the scope above.
Campus navigation is used by people who need it to get where they are going, including for accessibility. Please keep testing away from anything that would disrupt that.
What to Expect from Us
- We acknowledge reports within 3 business days.
- We will tell you our assessment, whether we are treating it as a vulnerability, and roughly when we expect a fix.
- We will keep you updated while we work on it, and let you know when it ships.
- We will credit you publicly if you would like to be credited.
We do not currently run a paid bug bounty program, so there is no monetary reward — but we read every report, and we are grateful for them.
For how we handle Personal Data, including the security and retention measures behind Ubikas, see the Privacy Statement.