Responsible Disclosure

Security Policy

We take security seriously. This policy explains how to report a vulnerability, what is in scope, our response timelines, and the safe-harbor guarantees we offer security researchers acting in good faith.

Last updated: 2026-06-01

01Scope

The following systems and surfaces are included in our responsible-disclosure program. Reports outside the listed scope will still be triaged, but do not qualify for safe-harbor protections under this policy.

In scope

Out of scope

02How to report

Send a clear, reproducible report to the address below. We acknowledge every legitimate report.

What to include

Please give us reasonable time to investigate and remediate before any public disclosure. We will work with you on coordinated disclosure timelines.

03Response SLA

We commit to the following response and remediation targets, measured from the time a valid report is received.

Acknowledgment and triage

Fix targets by severity

Critical
<72h
to patch
High
<7d
to patch
Medium
<30d
to patch
Low
<90d
to patch

04Safe Harbor

Good-faith security research that follows this policy is authorized and welcomed. We will not pursue legal action — civil or criminal — against researchers who:

If you are unsure whether your planned testing is authorized, email [email protected] first. We will respond quickly. When in doubt, ask before you act.

This safe-harbor applies to legal action initiated by us. We cannot grant immunity from third-party legal action, but if a third party brings a claim against you for research conducted in good faith under this policy, we will make our authorization clear to that party.

05Acknowledgments

Coming soon. Verified reporters will be credited here, with their consent, listed in chronological order of report receipt. If you prefer to remain anonymous, we will honor that choice.

How credit works

06Rewards

At this time we offer acknowledgment only. We do not pay monetary bounties for vulnerability reports.

A formal bug-bounty program may launch in the future. Researchers who reported high-impact issues during the acknowledgment-only period will be invited first when that program goes live.

07Encrypted contact

A PGP key for confidential disclosure is available on request. Send an email to [email protected] with the subject line PGP key request and we will reply with our current public key fingerprint and full ASCII-armored key.

For especially sensitive reports, you may also request a Signal contact or a one-time secure channel.

This policy is reviewed quarterly. Last review: 2026-06-01. RFC 9116 reference: /.well-known/security.txt