Security Policy
How to report a security vulnerability in Statiko, what is in and out of scope, what to expect from us, and the safe harbor we offer good-faith researchers.
Last updated: September 20, 2026
1. Introduction
Statiko ("Statiko", "we", "our", or "us") takes the security of the Service and the data it holds seriously. We welcome reports from security researchers and users who discover vulnerabilities in good faith and want to help us fix them.
This is a vulnerability disclosure policy, not a bug bounty program: we do not pay for reports (section 8), but we commit to taking every report seriously, keeping you informed, and crediting you if you wish.
2. Scope
This policy covers the systems we operate:
- the website and dashboard at statiko.io, including Creator Tools;
- the Statiko connector for AI assistants (the MCP server) at mcp.statiko.io;
- the APIs behind them and any other host under statiko.io;
- official Statiko browser extensions and mobile apps, where published.
3. Out of scope
Please do not report, and do not test for, the following:
- vulnerabilities in third-party services we rely on (Telegram, Cloudflare, billing providers, email providers, GitHub) — report those to the vendor directly;
- denial of service, volumetric attacks, or rate-limit testing of any kind;
- social engineering, phishing, or physical attacks against Statiko, its staff, or its users;
- output of automated scanners without a demonstrated, reproducible impact;
- best-practice findings without a working exploit: missing security headers, SPF/DKIM/DMARC configuration, clickjacking on pages with no sensitive action, software version disclosure, TLS cipher preferences;
- self-XSS or issues that require a victim to paste code into their own browser;
- content that is public on Telegram by design. The Service exists to show public posts, including their edit and deletion history; that is a feature, not a data leak. Objections to the processing of public channel data are handled under our Privacy Policy.
4. Rules of engagement
When researching, we ask you to:
- test only with accounts, channels, and organizations you own or are explicitly authorized to use;
- stop at the point of proof: once you can demonstrate the vulnerability, do not go further. Do not access, download, modify, or delete data that is not yours, and do not pivot to other systems;
- avoid anything that degrades the Service for other users;
- not use a vulnerability to extort or to demand payment as a condition of disclosure;
- keep the report confidential until we have fixed the issue or 90 days have passed since your report, whichever comes first. If you plan to publish, tell us beforehand so we can coordinate.
5. How to report
Email security@statiko.io in English. Please include:
- the affected host, URL, endpoint, or component;
- steps to reproduce, with a proof of concept (requests, screenshots, or a short script);
- the impact you believe the issue has and, if you can, a suggested fix;
- the name or handle to credit, if you would like to be credited (section 8).
Do not include other users' personal data in your report beyond what is strictly necessary to demonstrate the issue.
6. What to expect from us
- We acknowledge your report within 3 business days.
- We triage it and tell you the severity we assigned within 10 business days, and we may ask for more detail.
- We aim to fix confirmed vulnerabilities within 90 days of your report, and we will tell you when a fix has shipped.
- We keep you updated on progress and will not ignore or close a report without a reason.
If we disagree that something is a vulnerability, we will explain why.
7. Safe harbor
Security research carried out in accordance with this policy is authorized. We will not pursue civil action or a criminal complaint against you for it, and we will not report your research to law enforcement. If a third party initiates legal action related to research you conducted under this policy, we will make it known that you acted in accordance with it.
This safe harbor does not extend to actions outside the scope or rules described above, or to actions against third parties. It does not authorize you to break the terms of service of any other platform, including Telegram.
8. Recognition
We do not offer monetary rewards. With your consent, we credit reporters of confirmed vulnerabilities by name or handle in our acknowledgements and, for significant findings, in the release notes of the fix. If you prefer to remain anonymous, say so in your report.
9. Contact
Security reports and questions about this policy:
A machine-readable version of these contact details is published at /.well-known/security.txt. Our Privacy Policy and Terms and Conditions also apply.
10. Language
This policy may be provided in other languages for convenience. If the versions conflict, the English version prevails.