Report a vulnerability
Also published at /.well-known/security.txt.
What’s in scope
Section titled “What’s in scope”- The API at
api.cendarum.com - The desktop app and the
cendarumCLI - The cryptographic constructions described in this section — including “your stated construction does not achieve what you claim”
- This website
Findings in the not-defended tier of the threat model are already known and written down. If you think one of them is worse than we have characterised it, that is very much worth an email — mischaracterising a known limitation is a real defect.
What helps
Section titled “What helps”- What you did, what happened, and what you expected instead
- Which invariant or construction you think is violated, if you know
- Whether it needs an active server, a compromised device, or neither
Please don’t include real secrets in the report. If a reproduction needs a value, a placeholder and a description of its shape is enough.
What happens next
Section titled “What happens next”- We acknowledge within 72 hours, from a human.
- We tell you our assessment and a rough timeline, or say plainly that we disagree and why.
- We fix it, and — with your consent — credit you.
- If it changes a documented claim, the relevant page changes in the same release, and the threat model gains an entry if the finding turned out to be a limitation rather than a bug.
No bounty programme
Section titled “No bounty programme”There isn’t one, and we would rather say so than let you find out after doing the work. Cendarum is pre-launch and unpriced; there is no budget behind a bounty promise, and a bounty programme that can’t pay is worse than none.
If that changes, it will be announced here.
No PGP key yet
Section titled “No PGP key yet”There isn’t one published. If you need to send something you would rather not put in plain email, say so in a first message with no details and we will arrange a channel.
Please don’t
Section titled “Please don’t”- Run denial-of-service tests against the production API.
- Access, modify, or exfiltrate data belonging to anyone else. If you find a way to, stop and tell us — that is the finding.
- Use social engineering against us or our users.
Report in good faith and we will treat you accordingly.