Skip to content

Security & vulnerability disclosure

Last updated: 2026-06-05

We welcome reports of security vulnerabilities. This policy explains what is in scope, what is out of scope, how to report, what safe-harbour we offer, and what to expect in response. It is aligned with ISO/IEC 29147:2018 (vulnerability disclosure), the Coordinated Vulnerability Disclosure principles, and the CSIRT.PT guidance for the Portuguese national CSIRT.

Reporting channel

Email [email protected] with a clear technical write-up. The same address is published in our security.txt file at /.well-known/security.txt. For encrypted reporting, request our PGP public key in your first email.

Scope

In scope:

Out of scope:

Safe-harbour terms

We will not take legal action against good-faith security researchers who:

Safe-harbour is informal and does not override legal obligations to third parties whose systems may be implicated. When in doubt, ask first.

What to include in a report

Response SLAs

Bounty

We do not currently run a paid bug bounty. Outstanding research is acknowledged in the public changelog and on the recognised-reporters page below. We may, at our discretion, offer a thank-you of swag, free premium features (if/when introduced), or a charitable donation in your name.

Recognised reporters

We list, with their permission, the names of researchers whose reports have led to a material security fix. To opt out of public credit, mark your report “Anonymous”.

Public disclosure

We support coordinated disclosure. Once a fix is deployed and any affected users are notified, you are welcome to publish technical details. Where a CVE is appropriate we’ll work with MITRE or the relevant CNA.

Related policies

See our privacy policy Section 12 on security measures, the terms Section 6 on prohibited use, and the contact page for general support.