Security
Reporting a vulnerability
Last updated: 5 September 2026
Where to send it
Email official@dynoclub.app with “Security” in the subject. That address is monitored and is the single point of contact for security reports. You can write in English or Hungarian.
Please do not open a public issue, post the details publicly, or share them with anyone else until we have had a chance to fix the problem.
What we do with it
We will acknowledge your report within five working days, tell you whether we can reproduce it, and keep you informed while we work on a fix. If we decide not to act on something, we will say so and why rather than going quiet.
We are a one-person operation, and that is why this page promises five days rather than twenty-four hours. A promise that is kept is worth more than a fast one that is not.
What we ask of you
Give us enough to reproduce the problem. Do not access, change or delete anyone else’s data — if you need to prove an issue affects other accounts, tell us how and we will test it ourselves. Do not degrade the service for other climbers, and do not run automated scanning that generates significant load.
What you can expect from us
If you follow the above, we will not pursue any legal action against you for the research, and we will not report you to the authorities for it. We will credit you by name when the fix ships, if you want that; say so in your report.
We do not run a paid bug bounty. There is no money, and we would rather say that plainly than let you find out afterwards.
What is in scope
The Dyno Club iOS app, this website, and the servers they talk to at dynoclub.app. Third-party services we rely on — Supabase, Vercel, Hostinger, OpenStreetMap’s Overpass API — belong to those providers; report issues in them to the provider, though we would appreciate a copy.
Actively exploited vulnerabilities
Under the EU Cyber Resilience Act, a vulnerability in Dyno Club that is being actively exploited must be reported by us to the relevant national CSIRT and to ENISA within 24 hours of us becoming aware of it. If your report describes something already being exploited in the wild, please say so at the top of the email so we start that clock immediately.