Security
Report a vulnerability.
We are a security company. Finding something wrong with us is a service, and we would rather hear it from you than from an adversary.
How to report
One address, and a real reply.
Send findings to [email protected]. Include enough detail to reproduce, the affected surface, and how you would like to be credited.
We will acknowledge within three business days and tell you what we intend to do. If we disagree that something is a vulnerability, we will say why rather than going quiet.
Scope
What is in bounds.
| In scope | This website and any SafeKey Lab service you have been granted access to |
|---|---|
| Out of scope | Denial of service, social engineering, physical access, and testing against systems you do not have written authorization for |
| Third parties | Findings in a hosting or dependency provider should go to that provider; tell us as well and we will track it |
| Safe harbour | Good-faith research within this scope will not be met with a legal complaint from us |
| Disclosure | Coordinated. Tell us first, give us a reasonable window, and publish what you like afterwards. |