Found something?
Tell us.
We build an evidence recorder. If it has a flaw, we would rather hear it from you than read about it later. This page is the standing offer: how to reach us, what we will do, and the assurance that reporting in good faith will not be treated as an attack.
REPORT TO
security@alcyonesecure.com
FIRST RESPONSE
Within 24 hours
ENCRYPTION
No PGP key yet, say so and we will arrange a channel
If you make a good faith effort to follow this policy, we will treat your research as authorised. We will not pursue legal action against you, and we will not report you to law enforcement. If a third party brings action over research you conducted within this policy, we will say publicly that it was authorised.
We would rather receive an imperfect report than none at all. If you are unsure whether something is in scope, ask first, asking is always in scope.
What we want to hear about.
IN SCOPE
- +The Black Box desktop application for Windows
- +alcyonesecure.com and its subdomains
- +The hash chain, the encryption scheme, and the key derivation
- +The desktop sign in handoff and the custom URL scheme it uses
- +Authentication, session handling and account access
- +Anything that would let one person read another person's logs
OUT OF SCOPE
- −Reports produced only by an automated scanner, with no demonstrated impact
- −Missing headers or cookie flags with no exploitable consequence
- −Denial of service, volumetric testing, or anything that degrades the service for others
- −Social engineering of our team, our users, or our suppliers
- −Physical attacks, or anything requiring access to a device you do not own
- −The installer being unsigned: we know, it is documented, and it is on the roadmap
- −Third party services we do not control, unless the flaw is in how we configured them
Times, not intentions.
- WITHIN 24 HOURSWe acknowledge your report and tell you who is handling it.
- WITHIN 5 DAYSWe confirm whether we could reproduce it, and give you our assessment of severity.
- WITHIN 90 DAYSWe aim to have shipped a fix, or explained to you why we have not.
- ON RELEASEWe credit you by name or handle, unless you would rather we did not.
We are a small team. If we are going to miss one of these, we will tell you before the deadline rather than after it.
Use your own data
Test against accounts and devices you control. Do not access, modify or store anyone else's data. If you encounter someone else's data by accident, stop and tell us.
Do not degrade the service
No denial of service, no volumetric testing, no automated scanning that generates significant load.
Give us time
Let us fix it before you publish. Ninety days is the norm; if you need to move faster, say so and we will work to your timeline rather than argue about it.
Tell us enough to reproduce
Steps, a proof of concept, and what you think the impact is. A report we cannot reproduce is a report we cannot fix.
We do not run a bug bounty.
Not because we do not value the work, because we cannot currently fund it honestly, and a bounty we cannot pay is worse than no bounty at all. What we can offer is a fast response, a real fix, public credit, and a straight answer. If that changes, this page changes with it.
Researchers who have helped.
› no reports received yet
› this list is published as it fills
An empty list is the honest state of a product that has not shipped widely yet. We would rather show it empty than not have one.
MACHINE READABLE VERSION: /.well-known/security.txt · RFC 9116
