Skip to content

Security: myHerbDev/WebInsight

Security

SECURITY.md

SECURITY.md

WebInsight by myHerb

Last updated: January 2026

Overview

WebInsight is a sustainability‑focused web intelligence application developed by myHerb. We are committed to protecting user data, maintaining secure development practices, and ensuring that our platform operates responsibly and transparently.


Reporting a Vulnerability

We strongly encourage responsible disclosure.

Email: myherb.contact@gmail.com

Please include:

  • Description of the issue
  • Steps to reproduce
  • Potential impact
  • Relevant logs or proof‑of‑concepts

We acknowledge reports within 72 hours and provide a remediation timeline within 7 business days.


Scope

In scope:

  • WebInsight frontend & backend
  • API endpoints
  • Cloudflare Workers & Pages
  • myHerb‑managed infrastructure

Out of scope:

  • Third‑party services
  • Social engineering
  • User‑generated content

Security Practices

Secure Development Lifecycle

  • Code reviews
  • Dependency scanning
  • Static analysis
  • Least‑privilege access

Data Protection

  • HTTPS enforced
  • No plaintext sensitive data
  • Secure secret vaults
  • Access log audits

Infrastructure Security

  • Cloudflare WAF
  • DDoS protection
  • Rate limiting
  • Zero‑trust internal access

Sustainability‑Aligned Security

  • Reduced compute waste
  • Efficient caching
  • Minimal logging
  • Avoiding over‑provisioning

Responsible Testing Guidelines

Allowed:

  • Non‑destructive testing
  • Testing with your own accounts
  • Reviewing public endpoints

Not allowed:

  • DoS attacks
  • Automated scanning that degrades performance
  • Accessing others’ data
  • Attacking unrelated myHerb systems

Disclosure Process

  1. Private report
  2. Acknowledgment
  3. Investigation
  4. Fix deployed
  5. Optional researcher credit
  6. Public advisory (if needed)

We do not pursue legal action for good‑faith testing.


Contact

security@myherb.co.il

There aren’t any published security advisories