Security
Report concerns responsibly.
Security matters for any financial application, even before its first public release.
Current scope
The public website is static and does not provide accounts, accept financial credentials, connect to banks, or host user budget data. The private development environment is not in public testing scope.
Reporting
Email suspected vulnerabilities affecting this public website or project-owned public assets to admin@itsabudget.com. Include the affected URL, a clear description, reproduction steps, and potential impact.
Please do not access or modify data that is not yours, disrupt services, use automated high-volume testing, publish an unconfirmed issue, or include live credentials and sensitive financial information in email.
Response
Reports will be acknowledged and assessed as capacity allows. There is currently no bug-bounty program or promise of payment. Good-faith coordination is appreciated.