← Back to Protein Tracker

Security Policy

Last updated: June 2026

Reporting a vulnerability

If you discover a security vulnerability, please report it privately: do not post it publicly. Email the maintainer at contact@trackmyprotein.se with steps to reproduce, the affected area, and any proof-of-concept. We will arrange a secure channel if needed.

What to expect

Supported versions

The hosted application always runs the latest version. Security fixes are applied on a rolling basis; older snapshots are not maintained.

Scope

In scope: the application itself and its default deployment configuration. Out of scope: vulnerabilities in third-party dependencies that are already publicly known (these are tracked via automated dependency scanning), issues requiring a compromised host or physical access, and misconfigurations in a self-hosted deployment that deviate from the documented defaults.

How we handle vulnerabilities

A Software Bill of Materials (SBOM) is generated on every build, dependencies and the container image are monitored by Dependabot, and Trivy scans the dependencies and image on every build and weekly. This complements the app's audit logging and reflects our move toward alignment with the EU Cyber Resilience Act (CRA) vulnerability-handling expectations.

Contact

For any security-related questions: contact@trackmyprotein.se