Security and vulnerability disclosure

How the service is protected

PDF exports and downloads

PDF forms (for example, ICS-205) are generated on the Comm-Piler server from the saved plan. The browser receives each file as a standard HTTPS download from api.comm-piler.com with Content-Type: application/pdf and Content-Disposition: attachment, using a single-use link that expires after five minutes. No executable files, macros, or browser extensions are ever downloaded. Spreadsheet (XLSX/CSV) exports are also generated on the server.

Reporting a vulnerability

If you believe you have found a security issue, email [email protected] with the subject line “Security report”. Please include the affected URL, steps to reproduce, and the impact you observed.

Machine-readable contact: /.well-known/security.txt.