If you believe you found a security issue in the Tides Pilates platform, report it privately. We will investigate carefully, protect reporter confidentiality, and share material fixes when public disclosure is useful.
Practical response target
We aim to acknowledge contactable reports within two business days.
Safe harbor
Good-faith, bounded research following this policy will not be treated as an attack.
No bounty program
We do not promise payment, but we value clear, responsible reports.
This policy covers the Tides-owned web application and supporting APIs. It does not grant permission to test Clerk, Stripe, Resend, Twilio, Convex, Vercel, or other providers outside their policies.
We publish selected material findings after remediation. Routine hardening and low-risk maintenance may remain in internal records.
From March 18 through June 15, 2026, some legacy and pre-created account-linking paths could rely on a caller-controlled or insufficiently assured email claim. Tides corrected every linking branch and now accepts ownership only from trusted Clerk identity or webhook data.
From March 18 through April 21, 2026, an authenticated file-serving API verified sign-in but did not independently authorize each requested private storage object.
From March 18 through June 14, 2026, a diagnostic API could return a client profile and related membership, package, and booking information when supplied with that client's email address, without requiring authentication.