Security
Report a security issue.
If you believe you have found a vulnerability in a system operated by Aletarch, we want to hear about it. This page explains how to reach us and what we aim to do in response. Until a dedicated security contact is established, reports go to the address below.
- Report to
- hello@aletarch.com
- Subject line
- security
How to report
Email hello@aletarch.com with enough detail to reproduce the issue, and put “security” in the subject line.
Please include
- The affected system or URL
- Steps to reproduce, and what you were able to access
- The impact you observed
- Whether you retained any data, and confirmation you have deleted it
There is no dedicated security address or PGP key yet. If you are holding something sensitive, say so in the first email and we will arrange a channel before you send details.
Vulnerability disclosure policy — draft
Draft — these commitments are not yet in force
The response times, safe harbor, and scope below are a proposed policy awaiting counsel and are not yet commitments Aletarch has agreed to honour. Nothing in this section changes how to report an issue — the address and subject line above are the route today, and we would rather hear from you than have you wait for this to be finalized.
What to expect
When you report an issue under this policy, you can expect us to:
- Acknowledge your report within [5 business days — proposed]
- Work with you to understand and validate it, and share an initial assessment within [15 business days — proposed]
- Keep you informed as we work on a fix, within our operational constraints
- Credit you in our disclosure notes if you would like it
- Extend the safe harbor below to research conducted under this policy
These targets are set to what we can actually meet, not to what sounds impressive — we would rather publish a number we hit than one we miss.
What we ask of you
In return, we ask that you:
- Report anything you find promptly, through the address above
- Avoid violating anyone’s privacy, degrading our services, or destroying data
- Limit yourself to the minimum access needed to demonstrate the issue — and stop immediately and tell us if you encounter personal data
- Interact only with accounts you own, or have explicit permission to test
- Test only in-scope systems, and respect what is out of scope
- Give us [90 days — proposed] from your first report to fix the issue before disclosing it publicly, and talk to us if you need that to move
- Not use the issue for extortion
Safe harbor
When you conduct security research according to this policy, we consider that research to be:
- Authorized in view of any applicable anti-hacking laws, and we will not initiate or support legal action against you for accidental, good-faith violations of this policy;
- Authorized in view of relevant anti-circumvention laws, and we will not bring a claim against you for circumvention of technology controls;
- Exempt from restrictions in our terms of use that would interfere with conducting security research, waived on a limited basis for that purpose; and
- Lawful, helpful, and conducted in good faith.
You are expected to comply with all applicable laws. If a third party initiates legal action against you and you have complied with this policy, we will take steps to make known that your actions were conducted in compliance with it. This safe harbor applies only to legal claims under Aletarch’s control; it cannot bind anyone else.
If you are unsure whether something you want to try is consistent with this policy, ask us first — send the question to the address above before going any further.
Scope
In scope: https://aletarch.com.
Out of scope: third-party services Aletarch does not operate; social engineering of Aletarch people, contractors, or vendors; physical access to property or equipment; denial-of-service and volumetric or load testing; and any testing that would access data belonging to someone else.
Aletarch has no product infrastructure in public operation yet, so this site is the whole of the attack surface. [Additional domains, once Eidren is deployed — to be confirmed. Only domains Aletarch controls will be listed.]
Bounties
We do not currently pay bounties. We will say so here if that changes.