Report a vulnerability
Found a security issue in one of our sites or apps? Thank you. We want to hear about it. Here is how to reach us, and what you can expect back.
Include enough detail to reproduce the issue: the affected product or URL, the steps, the impact, and any proof of concept. If you would like to send an encrypted report, say so and we will arrange a key.
Scope
This covers software and services operated by Studio Labs Online LLC:
- Our sites: studiolabsonline.com, 3mfquickview.com, and list-tools.com.
- Our apps: 3MF QuickView for macOS, and the List Tools web tools.
Third-party platforms we merely use, such as our host or the Mac App Store, are out of scope here; report those to the vendor directly. If you are not sure whether something is in scope, email us and ask.
Good-faith safe harbor
If you make a good-faith effort to follow this policy, we will work with you to resolve the issue quickly. Good faith means, in short:
- Only interact with accounts, data, and systems you own or have permission to test.
- Avoid privacy violations, data destruction, and any interruption or degradation of service for others.
- Don't access or keep more data than you need to demonstrate the issue, and delete it once reported.
- Give us a reasonable chance to fix the issue before disclosing it publicly.
- Skip social engineering, physical attacks, and denial-of-service testing.
Our side of it, in plain terms: if your research follows this policy and is carried out in good faith, we will treat it as authorized. We will not report you to law enforcement over it, we will not bring a legal claim against you or seek damages for it, and we will not ask your employer or your host to act against you. If a third party brings a claim over research that followed this policy, we will make it known that your work was authorized by us.
If something you do falls outside this policy, we will look at whether you were acting in good faith before we decide how to respond, and we would much rather talk to you than escalate. If a piece of research would go past what is written here, email us first and ask.
This is a commitment about how we will act. It is not a contract, it does not bind anyone other than us, and it cannot authorize testing against systems or data belonging to someone else. Nothing here waives anyone's legal rights.
What to expect from us
- AcknowledgmentWe aim to reply within 5 business days.
- UpdatesWe will keep you posted as we investigate and work toward a fix.
- CreditWe are a small studio with no paid bug-bounty program, but we are glad to credit you for a valid report if you would like the acknowledgment.
Machine-readable contact
Our security contact is also published at /.well-known/security.txt, so scanners and tools can find it automatically.