Security & Vulnerability Disclosure
Effective: July 18, 2026 · Last updated: July 18, 2026
Keeping athlete, coach, and gym data safe is core to what Show Up Show Out LLC ("iVenza," "we," "us") does. We welcome reports from security researchers and users who believe they have found a vulnerability in our services, and we commit to working with you in good faith to understand and fix real issues quickly.
1. How to Report
Use either channel:
- The report form below - submitted over HTTPS directly to our triage queue.
- Email: help@susos.co - use this for anything the form won't take, such as a video or a file over 10 MB.
A good report includes:
- A clear description of the issue and its security impact.
- Steps to reproduce (URLs, request/response samples, or a proof of concept).
- The affected domain, endpoint, or app screen.
- Optionally, your contact details so we can send updates and credit you.
Anonymous reports are accepted - contact details are optional.
2. Scope
The following are in scope:
- ivenza.app and www.ivenza.app (this website).
- my.ivenza.app (the iVenza web app).
- api.ivenza.app (our API and serverless functions).
- The iVenza mobile apps for iOS and Android.
3. Out of Scope
- Denial-of-service, volumetric, or resource-exhaustion testing of any kind.
- Spam, social engineering, or phishing of iVenza staff, gyms, or users.
- Physical attacks against our infrastructure, offices, or people.
- Vulnerabilities in third-party services we use (for example Stripe, Supabase, Resend, Twilio, Cloudflare) - please report those to the vendor's own program.
- Automated scanner output without a demonstrated, working impact.
- Missing best-practice headers, SPF/DMARC nits, or version disclosures without a demonstrated security impact.
4. Our Commitment
- We will acknowledge your report within 3 business days.
- We will send a status update within 7 days of acknowledgment, and keep you informed as we triage and fix.
- We practice coordinated disclosure: please give us 90 days from your report before disclosing publicly, and we will work with you on timing if a fix needs longer.
5. Safe Harbor
We consider good-faith security research conducted under this policy to be authorized. We will not pursue or support legal action against you for accidental, good-faith violations of this policy while researching in scope. To stay within safe harbor:
- Do not access, modify, delete, or retain data that isn't yours. Use test accounts you create wherever possible.
- If you encounter personal data, stop immediately, do not save or share it, and report what happened.
- Do not degrade the service for other users.
- Do not demand payment as a condition of disclosure. Extortion voids safe harbor.
- Give us a reasonable opportunity to fix the issue before any public disclosure.
6. Recognition
We do not operate a paid bug bounty at this time. We are sincerely grateful for responsible reports, and with your permission we are happy to publicly credit you once the issue is fixed. Reports do not create an entitlement to payment or reward.
Report a Vulnerability
Submitted securely over HTTPS. No account needed. You can attach proof-of-concept files below; for a video or anything larger, email help@susos.co instead.
Thank you. We'll acknowledge it within 3 business days. If you left an email, updates will go there.