Skip to main content

Security

Security posture and public incident record for permtracker.app

Overview

Infrastructure is operated on SOC 2-compliant providers (Convex, Vercel). User data is encrypted at rest and in transit. Authentication uses email-verified one-time codes or Google OAuth; all passwords are salted and hashed using industry-standard algorithms. Outbound transactional mail is DKIM-, SPF-, and DMARC-authenticated.

Reporting a Vulnerability

If you believe you have discovered a security vulnerability in PERM Tracker, please report it privately by emailing security@permtracker.app. Include a description of the issue, steps to reproduce, and any proof-of-concept details. We’ll acknowledge your report within 72 hours and coordinate on disclosure timing. We don’t operate a paid bug-bounty program at this time, but we credit reporters who wish to be named in the incident record below.

Incident Record

Public-facing summaries of security-relevant incidents. Entries are kept permanently.

Unauthorized use of signup form to transmit unsolicited email

April 19-20, 2026  ·  Status: resolved

Resolved

What happened. Between approximately 2026-04-19 22:38 UTC and 2026-04-20 01:13 UTC, an unauthorized third party submitted a high volume of automated requests to the PERM Tracker public signup endpoint. The attacker placed unsolicited Turkish-language marketing content inside the submitted "name" field, causing that content to appear in standard transactional emails generated for the attacker- supplied recipient addresses.

What was affected. Approximately 139 attacker-chosen third-party email addresses received one or more messages. Upstream rate limits imposed by our email provider significantly constrained the volume that was actually transmitted. No customer data was accessed, viewed, exported, or modified. No existing PERM Tracker user accounts were affected.

Immediate action. The activity was identified and stopped on 2026-04-20 01:13 UTC. Additional safeguards were deployed the same day:

  • Server-side input validation on the affected endpoint, rejecting requests containing external URLs, non-alphabetic abuse patterns, or excessive length.
  • Transactional messages (welcome email and administrative notifications) are now generated only after email-verification is completed, preventing automated requests from triggering outbound email.
  • Cloudflare Turnstile anti-automation challenge added to the signup endpoint with server-side token verification.

If you received an unexpected email. If you received a message referencing permtracker.app that you didn’t expect, particularly one containing a link or promotional content in Turkish, please don’t click any links in that message. The content wasn’t authorized by PERM Tracker, wasn’t directed to you by us, and doesn’t reflect our product or services. You may safely delete the email. You won’t receive further messages from us unless you choose to sign up for an account directly at permtracker.app.

Coordinating with downstream providers. The phishing URL used in the attack has been reported to Google Safe Browsing, PhishTank, Netcraft, APWG, Bitly Trust & Safety, and Turkey's national CERT. Our email service provider has been notified proactively.

Last updated: April 20, 2026. This page will be amended when new security-relevant events occur. For questions about this page, contact security@permtracker.app.