How to report
Email security@skudo.org. If you would rather send it encrypted, ask for our OpenPGP key in a first message with no detail in it and we will reply with the key and its fingerprint.
We have not published a key at /.well-known/security.txt yet. Saying so is
better than pointing you at a file that does not have one.
Tell us what you found, how to reproduce it, and what an attacker could do with it. A working proof of concept helps and is not required.
What we promise
| Stage | Timing |
|---|---|
| Acknowledgement | Within 2 working days |
| First assessment | Within 7 days |
| Progress updates | At least every 14 days while the issue is open |
| Fix or documented decision | Within 90 days for most issues |
If we cannot meet a date we tell you why rather than going quiet.
Coordinated disclosure
We ask you to give us 90 days before publishing, and we will not ask for more unless the fix requires coordination with a third party, in which case we will explain and agree a date with you.
We will not ask you to stay quiet indefinitely, and we will not use a legal threat to obtain silence. If we fail to fix something in a reasonable time, publishing is a legitimate response and we will say so publicly rather than dispute it.
Recognition, and no reward
We publish the names of people who report valid issues, if they want to be named.
There is no monetary reward. The service is free and funded by voluntary support, and we would rather say so than advertise a bounty we cannot pay. If that changes, this page changes with it.
Rules of engagement
Testing is welcome against your own account and your own aliases.
Please do not:
- access, modify or delete data belonging to anyone else;
- run automated scans that degrade the service for other users;
- attempt denial of service, physical attacks, or social engineering of our people or our suppliers;
- read, intercept or store mail that is not yours.
If you accidentally reach somebody else's data, stop, tell us, and delete what you have. We will treat that as part of the report and not as a violation.
What is in scope
The application at app.skudo.org, the site at skudo.org, the mail servers
handling alias domains, and the published clients.
Out of scope: findings from automated scanners with no demonstrated impact, missing hardening headers with no exploit path, reports about software we do not run, and social engineering.
Safe harbour
If you follow this policy, we will not pursue or support legal action against you for your research, and we will say so to anyone who asks.
This is a commitment we make and can keep. It cannot bind a third party, and it cannot bind a public authority.