Skip to content

Security Policy

Last updated: September 2026

Reporting a Vulnerability

We take security seriously. If you discover a security vulnerability, please report it responsibly:

Please include:

  • Description of the vulnerability
  • Steps to reproduce
  • Potential impact
  • Any suggested fixes

Our Commitment

  • We will acknowledge receipt within 48 hours
  • We will provide a preliminary assessment within 5 business days
  • We will keep you informed of progress
  • We will credit you in our acknowledgments (unless you prefer anonymity)

Scope

This policy applies to:

  • 2-heroes.com and all subdomains
  • API endpoints under api.2-heroes.com
  • Email infrastructure

Out of Scope

  • Social engineering attacks
  • Physical security
  • Third-party services not under our control
  • Rate limiting / DoS (handled by infrastructure)
  • Missing security headers on non-sensitive pages

Security Measures

  • Content Security Policy (CSP) enforced
  • HTTP Strict Transport Security (HSTS)
  • Rate limiting on all endpoints
  • Bot detection and blocking
  • Input validation and sanitization
  • Secure headers (X-Frame-Options, X-Content-Type-Options, etc.)
  • No sensitive data stored client-side
  • Dependencies regularly scanned and updated