CmdTab app icon

CmdTab

macOS window switching

Menu

Security

CmdTab security disclosure

Use this page to report security issues privately and understand which systems, versions, and testing methods are currently in scope.

Last reviewed:

Current documented app: 1.0.0

How to report a vulnerability

Report suspected security issues privately to tohsh17@gmail.com.

Include the affected URL, app version or build, macOS version, feature, clear reproduction steps, impact, logs that do not expose other people's data, and a minimal proof of concept when one is needed to validate the issue.

Current scope

In scope: the cmdtab.net website and APIs, dashboard authentication, analytics ingestion, trial registration, checkout and webhook handling, license generation and delivery, the native CmdTab app, update and release packaging, and the public repository configuration.

Third-party platforms such as Vercel, Resend, GitHub, and the configured commerce provider are governed by their own disclosure programs unless the issue is caused by CmdTab's integration or configuration.

Safe testing boundaries

Do not access data that is not yours, publish an unpatched vulnerability, destroy or alter production data, send malware, conduct social engineering, or perform sustained denial-of-service testing.

Use the minimum traffic and data needed to demonstrate the issue. Stop testing and report immediately if you encounter personal, licensing, or payment information belonging to another user.

Response and remediation

Reports are reviewed for reproducibility, affected versions, user impact, and available mitigations. CmdTab may request clarification or a safer proof of concept before confirming the issue.

No guaranteed response time or public bug-bounty payment is promised today. Coordinated disclosure timing should be agreed before technical details are published.