Security

Responsible reporting.

How to report a suspected vulnerability affecting Teahood's public company website or related company systems.

Published July 27, 2026No public bug-bounty program

Security overview

Teahood uses measures designed to protect its public website and company communications, including HTTPS, infrastructure security controls, restricted administrative access, minimal public data collection, and version-controlled publishing.

This page does not claim independent certification, a specific compliance framework, or that any online system is completely secure.

Report a suspected issue

Email [email protected] with the subject “Security report.” For the public company website, the same contact is published in security.txt.

If the report affects Nodebase account or Worker security, state “Nodebase security” in the subject and identify the affected product surface without including credentials or private user content.

What to include

  • a concise description of the issue and its potential impact;
  • the affected URL, product surface, or version;
  • steps that reproduce the issue using your own account or data;
  • relevant timestamps and sanitized screenshots or logs; and
  • a safe way to contact you for follow-up.

Do not include passwords, login codes, private keys, tokens, customer data, or unnecessary personal information.

Testing boundaries

Good-faith reporting does not authorize unrestricted testing. Do not:

  • access, alter, retain, or disclose another person's data;
  • degrade availability, send denial-of-service traffic, or run high-volume automated scans;
  • use social engineering, phishing, physical intrusion, or attacks against employees or providers;
  • exfiltrate data, deploy malware, establish persistence, or move laterally; or
  • violate law or third-party terms.

Stop testing when you confirm a potential issue and report it with the minimum evidence needed.

Response and disclosure

We will review good-faith reports and may contact you for clarification. Teahood does not currently promise a fixed response or remediation time and does not operate a public reward program.

Please allow reasonable time to investigate and address a confirmed issue before public disclosure. Any coordinated disclosure arrangement must be agreed separately in writing.

Nodebase security information

Nodebase has product-specific network, device, Worker, account, and operational security boundaries. Refer to the Nodebase Privacy Policy and Nodebase Terms for current public commitments.