# Reporting a security vulnerability

## How to report

Email security@skudo.org. If you would rather send it encrypted, ask for our
OpenPGP key in a first message with no detail in it and we will reply with the
key and its fingerprint.

We have not published a key at `/.well-known/security.txt` yet. Saying so is
better than pointing you at a file that does not have one.

Tell us what you found, how to reproduce it, and what an attacker could do with
it. A working proof of concept helps and is not required.

## What we promise

| Stage | Timing |
| --- | --- |
| Acknowledgement | Within **2 working days** |
| First assessment | Within **7 days** |
| Progress updates | At least every **14 days** while the issue is open |
| Fix or documented decision | Within **90 days** for most issues |

If we cannot meet a date we tell you why rather than going quiet.

## Coordinated disclosure

We ask you to give us **90 days** before publishing, and we will not ask for
more unless the fix requires coordination with a third party, in which case we
will explain and agree a date with you.

We will not ask you to stay quiet indefinitely, and we will not use a legal
threat to obtain silence. If we fail to fix something in a reasonable time,
publishing is a legitimate response and we will say so publicly rather than
dispute it.

## Recognition, and no reward

We publish the names of people who report valid issues, if they want to be named.

There is no monetary reward. The service is free and funded by voluntary
support, and we would rather say so than advertise a bounty we cannot pay. If
that changes, this page changes with it.

## Rules of engagement

Testing is welcome against your own account and your own aliases.

Please do not:

- access, modify or delete data belonging to anyone else;
- run automated scans that degrade the service for other users;
- attempt denial of service, physical attacks, or social engineering of our
  people or our suppliers;
- read, intercept or store mail that is not yours.

If you accidentally reach somebody else's data, stop, tell us, and delete what
you have. We will treat that as part of the report and not as a violation.

## What is in scope

The application at `app.skudo.org`, the site at `skudo.org`, the mail servers
handling alias domains, and the published clients.

Out of scope: findings from automated scanners with no demonstrated impact,
missing hardening headers with no exploit path, reports about software we do not
run, and social engineering.

## Safe harbour

If you follow this policy, we will not pursue or support legal action against
you for your research, and we will say so to anyone who asks.

This is a commitment we make and can keep. It cannot bind a third party, and it
cannot bind a public authority.
