Security
Security at SHY
Security work at SHY is continuous. This page covers how to report a vulnerability and, in plain language, how we protect the service.
Reporting a vulnerability
If you believe you have found a security vulnerability in SHY, email jonah@shyapps.com with "Security report" in the subject. Include steps to reproduce and the impact you believe it has. Do not include passwords, authentication codes, payment data, or another person's private information. We do not publish a response-time commitment.
Testing ground rules
- No denial-of-service testing and no automated scanning against production.
- Never access, modify, or delete another person's data. Use accounts you created.
- No social engineering of SHY staff or users, and no physical attacks.
Good-faith research that follows these rules is welcome, and SHY will not pursue or support legal action against it. In scope: shyapps.com and the SHY app; third-party services we rely on are governed by their own policies. Do not conduct testing that could affect people, data, or service availability.
How SHY protects data
All traffic is served over HTTPS with HTTP Strict Transport Security (preloaded), and the site ships a strict Content-Security-Policy with frame embedding blocked. Accounts authenticate with short-lived signed tokens. Data access is enforced in the database itself with row-level access rules, so a signed-in account can read only what it is authorized to see — matching, messaging, and blocking authority live server-side, not in the client. Automated release checks block server secrets from ever shipping in the public app, and every production release is traceable to reviewed code.
Everything on this page is limited to what we can verify today; third-party certifications and audit results will be published here as they complete.
Last reviewed: August 21, 2026.