Security & Vulnerability Disclosure

Last updated July 25, 2026

We take the security of residents’ data seriously. If you have found a vulnerability in neighbors.fyi, we want to hear about it. This page explains how to report one, what we consider in scope, and our commitment to researchers who act in good faith. It is issued by Loomfield Labs, LLC, a Florida limited liability company doing business as neighbors.fyi.

Our machine-readable contact details are published at /.well-known/security.txt.

1. Reporting a vulnerability

Email security@neighbors.fyi with a description of the issue and clear steps to reproduce it. Where relevant, include the affected URL or endpoint, a proof of concept, and the impact you believe it has. Please report only your own findings, and give us reasonable time to investigate and fix an issue before sharing it publicly.

We do not run a paid bug-bounty program at this time. We are grateful for every valid report and will credit you by name if you would like the recognition.

2. What is in scope

In scope:

  • The neighbors.fyi web application and the software running on its community subdomains (*.neighbors.fyi), including any custom domain a community has attached to its portal.
  • The admin portal (admin.neighbors.fyi).
  • Our email and payment integrations as they appear inside those applications.

Where to test. Please do your testing against our public demo at neighbors.fyi/demo, or against a community you personally belong to and have permission to test. Do not test against a live community you are not a member of. Those subdomains hold real residents’ names, home addresses, and private messages, and probing them is the one thing that turns good-faith research into a privacy incident we are obliged to report.

The demo runs the same application code as every community, so most findings there apply everywhere. Be aware of two limits: the demo is read-only, so every write is rejected by design, and its guest account has no administrative capability. If an issue can only be shown against a writable or admin-only surface, or against email delivery, email us and we will arrange a safe way to reproduce it rather than have you test it on a live community.

If you believe a vulnerability can only be demonstrated against a live community, stop and email us first. We will arrange a safe way to reproduce it.

Out of scope:

  • Third-party services we build on (for example Supabase, Vercel, Stripe, Resend, and Google), which run their own disclosure programs.
  • Reports that require a compromised device, a rooted phone, or a stolen account to reproduce.
  • Findings with no demonstrated impact: missing security headers on their own, rate-limiting on non-sensitive endpoints, self-XSS, and clickjacking on pages with no sensitive action.
  • Volumetric denial-of-service and any test that degrades service for real residents.

3. Safe harbor for good-faith research

We will not pursue or support legal action against anyone who discovers and reports a vulnerability in good faith and in line with this policy. Good faith means you make a genuine effort to avoid privacy violations, data destruction, and any interruption to our service, and you stop and notify us as soon as you encounter data that is not your own.

Activity that follows this policy is authorized under Section 6 of our Terms of Service, which carries an express security-research exception, and so does not breach them. If a third party brings legal action against you for activity that followed this policy, we will make it known that your actions were authorized.

4. Rules of engagement

Please do:

  • Test only against accounts and data you own or have explicit permission to use.
  • Limit yourself to the minimum interaction needed to demonstrate an issue.
  • Report promptly, and keep the details confidential until we have resolved it.

Please do not:

  • Access, modify, or delete another resident’s data.
  • Run automated scans that degrade service, or attempt a denial-of-service.
  • Use social engineering, phishing, or physical attacks against our team, residents, or vendors.
  • Disclose the issue publicly before we have had a reasonable chance to fix it.

5. What happens after you report

We aim to acknowledge your report quickly, keep you updated as we investigate, and let you know when the issue is resolved. Timelines depend on the severity and complexity of the finding. If a report reveals an incident affecting personal data, we follow the notification commitments in our Privacy Policy and Data Processing Addendum. Thank you for helping keep neighbors.fyi and its communities safe.