Skip to content

Security: RoxyAPI/sdk-typescript

Security

SECURITY.md

Security policy

Reporting a vulnerability

Found a security issue in any RoxyAPI repo or in the API itself? Do not open a public issue. Use the contact form at https://roxyapi.com/contact and select the security category.

We acknowledge reports within 48 hours and target a fix within 7 days for critical issues.

Scope

In scope:

Out of scope:

  • Vulnerabilities in third-party dependencies that already have a published advisory
  • Rate-limit bypass using valid paid API keys (rate limits are commercial limits, not security boundaries)
  • Self-XSS or social-engineering scenarios

Acknowledgement

Researchers who report valid issues responsibly are credited in our security log if they choose to be named.

There aren’t any published security advisories