Back to Home
Report a security issue
Last updated: October 6, 2026
If you think you've found a security issue in Champ, please tell us before anyone else. Email hello@champ.plus and start the subject line with "Security". A person reads every report, and we reply within 48 hours.
What to send
- What you found and where: the URL, the API endpoint or the app screen
- The steps to reproduce it, and what an attacker could do with it
- Your app version and iOS version, if the issue is in the app
- Whether and how you'd like to be thanked
In scope
- The Champ app for iPhone
- The backend the app talks to: Champ's Firebase database, storage and cloud functions
- The champ.plus website and its API (everything under champ.plus/api/)
Out of scope
- Denial of service, load testing, or anything else that slows the service down for other people
- Social engineering or phishing of Champ users or of the people who run Champ, and physical attacks
- Bugs in the third-party services Champ uses, such as Apple, Google and Firebase, OpenAI, RevenueCat and Resend. Please report those to the vendor. How Champ configures them is in scope.
Safe harbor for good-faith research
If you follow this page in good faith, we'll treat your research as authorized. We won't take legal action against you or ask anyone else to. Good faith means you:
- Use only your own accounts, and test only what you need to show the issue
- Stop as soon as you reach data that isn't yours, and don't keep, change, delete or share it
- Don't degrade the service for anyone else
- Give us a fair chance to fix the issue before you talk about it in public. We'll agree on a date with you.
No bounty
Champ doesn't pay bug bounties. If you'd like, we'll thank you by name on this page once the fix is live.
What happens next
- We reply within 48 hours to confirm we have your report.
- We keep you posted while we work on it, and tell you when the fix is live.
- The same inbox handles account help and billing, so the "Security" subject line helps us spot your report quickly.
The same contact details are published for automated tools at champ.plus/.well-known/security.txt.