Security policy
If you believe you have found a security vulnerability in MobiObs, please tell us privately so we can fix it before it is disclosed.
How to report
Email contact@mobiobs.com with the subject line “Security report”, or use the contact form with the topic Security report. Please include:
- what is affected: the app and its version, the device and operating system, the web UI, licence keys or this website;
- the steps to reproduce the problem, and what an attacker could achieve;
- any proof-of-concept code, captures or screenshots;
- how you would like to be credited, if at all.
Machine-readable contact details are in /.well-known/security.txt.
In scope
- The MobiObs apps for Android, iOS, iPadOS and desktop, including the collectors and the web UI they serve on the local network.
- Licence key verification and issuing.
- mobiobs.com and its forms.
Reports about missing best-practice headers without a demonstrated impact, denial of service by flooding, social engineering and physical attacks are out of scope.
While you investigate
- Test only against devices and accounts that you own or are authorised to test.
- Do not access, change or delete data that belongs to others, and stop as soon as you have shown the problem.
- Do not degrade the website or other people's use of it.
- Give us a reasonable time to fix the problem before you disclose it publicly.
We will not pursue or support legal action against anyone who reports a vulnerability in good faith and follows these rules.
What happens next
We will confirm that we received your report, keep you informed while we investigate and fix it, and credit you in the release notes if you wish. MobiObs is a small team and does not currently offer a paid bug bounty.