Skip to content

Security: apiverve/username-checker-node-tutorial

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

We take security seriously at APIVerve. If you discover a security vulnerability, please report it responsibly.

How to Report

Email: security@apiverve.com

Please include:

  • Description of the vulnerability
  • Steps to reproduce
  • Potential impact
  • Any suggested fixes (optional)

What to Expect

  • Acknowledgment: Within 48 hours
  • Initial Assessment: Within 5 business days
  • Resolution Timeline: Depends on severity, typically 30-90 days

Scope

This policy applies to:

  • APIVerve REST APIs (api.apiverve.com)
  • APIVerve websites (apiverve.com, docs.apiverve.com, dashboard.apiverve.com)
  • Official SDKs and client libraries

Out of Scope

  • Social engineering attacks
  • Denial of service attacks
  • Issues in third-party dependencies (report to upstream)
  • Issues requiring physical access

Safe Harbor

We will not take legal action against researchers who:

  • Act in good faith
  • Avoid privacy violations and data destruction
  • Do not exploit vulnerabilities beyond proof of concept
  • Report findings promptly and privately

Security Best Practices

When using APIVerve APIs:

  1. Protect your API key - Never expose it in client-side code
  2. Use HTTPS - All API calls should use HTTPS
  3. Rotate keys - Periodically rotate your API keys
  4. Monitor usage - Check your dashboard for unusual activity

Contact

There aren’t any published security advisories