The Tribe

Reporting a security problem

The Tribe keeps real, personal information for the people who join: names, dates of birth, sometimes a CV or the sort of things people only share when they trust you. Keeping that safe matters to us. If you have found a weakness in this website, this page tells you how to let us know, and what we promise you in return.

How to reach us

Email admin@thetribe.cloud and put the word Security in the subject line. Tell us what you found and, if you can, the steps to see it for ourselves. A short, clear write-up helps us fix a real problem quickly. If what you have found is sensitive, say so, and we will reply with a private way to share the details.

What we promise you

We read every genuine report. We will acknowledge yours, usually within a few days, keep you updated as we look into it, and fix real problems as fast as we sensibly can. If you would like the credit, we will thank you by name once it is sorted. If you would rather stay anonymous, that is fine too.

We will be honest about one thing: The Tribe is new and is not making money yet, so we cannot offer a cash reward for reports. What we can offer is a real thank you, a fast and respectful reply, and the knowledge that you helped keep a community safe.

What we ask in return

So that good-faith research stays good for everyone, please:

If you act in good faith and follow these simple rules, we will treat your work as the help it is. We will not pursue or support legal action against you for research done this way.

What this page is not for

This page is about technical weaknesses in the website itself. Two related things live elsewhere:

There is a machine-readable version of this policy at /.well-known/security.txt, following the security.txt standard (RFC 9116).