Security policy

Report security problems privately.

A clear report helps Pull Tally protect developers and their GitHub access. Please send suspected vulnerabilities before sharing them publicly.

Last reviewed: 8 September 2026

How to report a vulnerability

Email dataprotection@pulltally.com with the subject Pull Tally security report.

Please include what you found, the affected page or component, reproduction steps, and the possible impact.

Remove credentials, personal data, and private repository content from the report when they are not necessary. If sensitive evidence is necessary, ask for a safer transfer method first.

What happens next

Pull Tally will acknowledge the report, check its scope, and keep you informed about material progress. A response time cannot be guaranteed, but reports that risk user data or GitHub access receive priority.

Please allow time for investigation and a fix before public disclosure. Pull Tally will coordinate a disclosure date when the report is valid.

Testing boundaries

Only test accounts, organizations, and repositories that you own or have explicit permission to use.

  • Do not access, change, retain, or share another person's data.
  • Do not use social engineering, phishing, denial-of-service attacks, or high-volume automated scans.
  • Do not disrupt the service or weaken another user's access.
  • Stop testing and report the problem if you reach credentials, private data, or another account.

This policy does not give permission to break the law or access third-party systems. No bounty or other payment is offered.

Supported service

Security fixes support the current service at pulltally.com.

Current safeguards

  • The GitHub App requests read-only pull request and metadata permissions.
  • GitHub credentials are protected before storage. The protection keys use a separate certificate.
  • Authentication cookies are secure and HTTP-only. Sessions have idle and absolute expiry limits.
  • GitHub webhook signatures are verified, and duplicate delivery IDs are rejected.
  • Pull request details are cached in server memory for up to five minutes instead of stored in the database.
  • Account deletion blocks access first and prevents old backups from restoring it.

These controls reduce risk but cannot promise perfect security. See GitHub access and the privacy policy for more detail.

Pull Tally lost its connection. Reload

Reconnecting…

Connection interrupted. We’re trying to reconnect.

Displayed results may be out of date. Actions are paused until you reconnect.