Homier
  • Features
  • Pricing
  • FAQ
  • Blog
  • Contact
  • About
  • Log In
FeaturesPricingFAQBlogContactAbout
Log In

Security Policy

Last Updated: March 26, 2026

At Homier, we take the security of our platform seriously. This policy outlines how to responsibly disclose security vulnerabilities and what to expect when working with our team.

Reporting a Vulnerability

If you believe you've found a security vulnerability in the Homier platform, we encourage you to report it to us through our coordinated disclosure process:

  1. Send details of the vulnerability to support_team@livehomier.com
  2. Include steps to reproduce the issue, along with any supporting materials (screenshots, videos, etc.)
  3. If possible, include information about the potential impact of the vulnerability

What to Expect

When you submit a security report, you can expect the following from the Homier team:

  • We will acknowledge receipt of your report within 7 business days
  • We will provide an initial assessment of the report within 30 days
  • We target remediation of confirmed vulnerabilities within 90 days. Complex or infrastructure-level issues may require additional time.
  • We will make reasonable efforts to notify you when a reported vulnerability has been addressed

Scope

This security policy applies to all aspects of the Homier platform, including:

  • The Homier web application
  • Homier-controlled Firebase configuration, Firestore security rules, Firebase Storage rules, and Cloud Functions
  • Homier APIs and backend services
  • Note: vulnerabilities in Google's underlying Firebase or GCP infrastructure should be reported directly to Google

Safe Harbor

Homier is committed to working with security researchers who responsibly report vulnerabilities. We will not pursue legal action against researchers who:

  • Make a good faith effort to avoid privacy violations, data destruction, or service interruption
  • Do not exploit vulnerabilities beyond what is necessary to confirm the vulnerability exists
  • Do not share discovered vulnerabilities with others before they are fixed
  • Provide us reasonable time to address vulnerabilities before any public disclosure

Out of Scope

The following types of reports are typically not considered valid security vulnerabilities:

  • Reports of vulnerabilities in third-party applications or services that we don't control
  • Social engineering attacks such as phishing
  • Denial of Service (DoS) attacks
  • Reports of issues that are solely related to user behavior
  • Using publicly available data to demonstrate potential theoretical risks without actual exploitability

Recognition

While we don't offer a bug bounty program at this time, we appreciate the security community's efforts in helping us maintain a secure platform. With permission, we will acknowledge security researchers who have helped improve our security in our security acknowledgments.

Changes to This Policy

We may update this security policy from time to time. The most current version will always be available at this URL.

Contact Information

If you have any questions about this security policy, please contact us at:

Homier, LLC
Email: support_team@livehomier.com

Homier

The simple way to share your vacation home with friends and family.

Product

  • Features
  • Pricing
  • FAQ
  • Blog

Company

  • About
  • Contact

Legal

  • Terms of Service
  • Privacy Policy
  • Privacy choices
  • Security Policy

Connect

© 2026 Homier. All rights reserved.