← Galley

Security.

Last updated 25 July 2026

Found a security problem in Galley? Please tell us. We read every report, we act on them quickly, and we will never take issue with research done in good faith.

How to report

Email studio@publikable.com with enough detail to reproduce the issue — the URL or flow affected, what you did, and what you observed. Machine-readable details live at /.well-known/security.txt (RFC 9116). Please report privately by email rather than in a public forum, and give us a reasonable window to fix the issue before any public disclosure.

What to expect

We will acknowledge your report within 3 working days, keep you updated as we investigate, and tell you when the fix ships. We don’t run a paid bug bounty — Galley is a small studio tool — but we gladly credit reporters who want to be named.

Scope

In scope: galley.publikable.com and its API routes, including the quote-upload flow and the Canva connection. Worth knowing before you dig: your manuscript never leaves the browser, there are no user accounts, and Canva tokens are never stored server-side — several classic attack surfaces simply don’t exist here. Out of scope: denial-of-service and volumetric testing, spam to the studio inbox, social engineering, and third-party services we don’t operate (Canva, Vercel, Supabase — report those to their own programmes).

Good-faith research

If you make a genuine effort to avoid harming others’ data, privacy, and service availability — test against your own data, stop when you’ve proven the issue, and report it promptly — we consider that authorised good-faith research and will not pursue legal action over it.

Security — Galley