Security Policy
Last updated:
WorkoutGen is a project built by two friends in France - a developer and a fitness coach - with a single goal: to make personalized fitness free and accessible to as many people as possible.
If you found a vulnerability, let us know. We do not offer a bug bounty, but every actionable report is reviewed and prioritized based on its impact.
Responsible researchers are publicly credited in our Hall of Fame. No reward is worth knowing you helped protect thousands of people who are just trying to take care of themselves.
How to report a security issue
Write to us directly. We reply within 72 hours - no ticketing system, no corporate black hole, just us.
Email: security@workoutgen.app
RFC 9116 file: /.well-known/security.txt
If you have multiple findings, please send them in separate reports if possible. One vulnerability per email makes triage and credit attribution much clearer for everyone.
Please include
- Clear reproduction steps
- The exact scope tested (URL, endpoint, user flow, account type, environment)
- The date and time of the test in UTC
- A measurable impact
- Sanitized requests and responses, logs, or HAR files when relevant
- A proof of concept or screenshots if possible
- For session or replay issues, the exact delay between actions and whether the issue persists after a refresh or after more than 60 seconds
Scope
This policy covers workoutgen.app, my.workoutgen.app, and all our associated services. If you are not sure whether something is in scope, ask first - we prefer a false alarm to a missed real issue.
Reports that rely solely on browser extensions, local malware, self-XSS without privilege boundaries, or third-party behavior with no demonstrated impact on WorkoutGen are generally out of scope.
What we ask of you
- Do not access user data beyond what is strictly necessary to prove the existence of the vulnerability
- Do not perform denial of service tests - our infrastructure is tight and every request has a cost
- No social engineering, phishing, or physical attacks
- If you accidentally stumble upon something sensitive, stop and let us know - we will keep it confidential and work with you, not against you
- Please keep testing rate-limited and avoid any automation that could degrade the service
- Please mask active tokens, secrets, and personal data before sending proof
What you can expect from us
We will acknowledge receipt within 72 hours and be transparent about what we find and what we can reasonably do. No legal action will be taken against good-faith research that complies with this policy, avoids any privacy violations, and does not disrupt the service.
We may classify a report as confirmed, partially confirmed, informative, or not reproducible. If we do not validate part of the report, we will explain why.
Fix timelines depend on severity, complexity, and our capacity. High-impact vulnerabilities are addressed as a priority. The Hall of Fame remains discretionary and primarily rewards valid or materially useful reports.
Hall of Fame
These researchers chose to help rather than exploit. We are grateful to them.
| Researcher | Finding | Specialty | Year | Profile |
|---|---|---|---|---|
| Pavan Baile | Clickjacking (X-Frame-Options) | Web Security | 2026 | |
| Siva Karthik Reddy | Broken Session Management | Red Teaming | 2026 | |
| Paladugu Gopichandu | Email Change Without Verification | Web Security | 2026 | |
| Sairam Batraju | Password Reset Rate Limiting | Web Security | 2026 | |
| Harshini Priya R | CORS Misconfiguration | Web Security | 2026 | |
| THIVYA PADMINI S | Client-Side Session Metadata Exposure | Web Security | 2026 |