Skip to content
SIAT PAPER 2026Open the research page
Cryptoverso

Responsible disclosure

How to report a security problem in this site or in the platform, what happens next, and how quickly. This is a policy, not a paid bounty programme.

Draft: we wrote this text ourselves and a lawyer has not reviewed it yet. The review happens before go-live.

Who this page is for

It is for anyone who finds a security defect in what we publish and wants to tell us before someone else finds it. A written policy exists so that this decision — telling us, and how — does not have to be made at the moment the discovery has already happened.

The contact point is repeated in a machine-readable file, at /.well-known/security.txt on this site, in the format prescribed by RFC 9116: it is the first place a researcher looks, and it points back to this page.

Where to write

Write to info@cryptoverso.net, with “security” in the subject line.

It should be said plainly: that is not yet a dedicated security mailbox, but our general contact address. It is a stated fallback, and while it lasts we still handle security reports ahead of everything else. The day a dedicated mailbox exists, this line and the machine-readable file will change together.

A useful report includes: the page or endpoint involved, the steps to reproduce, what you obtained and what you expected to obtain, and the date and time of the attempt. A screen recording or a saved request is worth more than a long description.

You do not have to tell us your name. If you prefer to stay anonymous the report still counts: the only thing lost is our ability to keep you informed.

What happens next, and how quickly

  • we confirm receipt of the report as soon as we can: our stated target is within five working days;
  • we tell you whether we reproduced the problem and how we classified it, aiming to do so within fifteen working days;
  • if the problem is confirmed, we keep you updated until it is closed, and whenever its status changes;
  • when it is fixed we tell you, and if you wish we credit you publicly for the finding — under whichever name you prefer, or under none.

These are stated targets, not contractual deadlines, and the reason is written two paragraphs above: the address is our general one, not a dedicated mailbox with a rota behind it. Promising you a deadline that no process supports would be worse than not promising it — the day the dedicated mailbox and the rota exist, these lines will become deadlines again and will say so. If a problem is severe and involves other people’s data, our first move is to contain it rather than discuss it: in that case a reply may come later, but it comes after something has already been done.

What is in scope, and what is not

In scope: this site, the analysis platform and our subdomains, together with the code we publish in the lab repositories.

Out of scope:

  • third-party services we use — report those to them, through their own channels; if you are not sure who to write to, ask us;
  • attacks aimed at making a service unavailable, and load testing of any kind: they demonstrate nothing we do not already know, and they degrade the service for whoever is using it;
  • social engineering against us, our collaborators or our users, and test messages sent through the public forms;
  • the raw output of an automated scanner without a demonstration of impact: a list of missing headers is not a report, it is a scan;
  • mail or domain configuration findings without a concrete abuse scenario attached.

What we ask of you

  • do not disclose the problem publicly until it is fixed, or in any case for ninety days from the report — if by then we have neither fixed it nor explained why, you are free to publish;
  • stop as soon as you have proof that the problem exists: no access to other people’s data beyond the strict minimum, no modification and no deletion of data that is not yours;
  • do not degrade the service for others, and do not use the finding to obtain something from us or from anyone else.

If you respect these points, we consider your research to have been carried out in good faith and we will take no legal action against you for carrying it out.

Why there is no reward

A paid bounty programme has to be run: someone has to triage, decide what each report is worth, pay, and answer whoever disputes the amount. Promising money that nobody has budgeted and nobody administers is worse than not promising it — it turns a collaborative relationship into a dispute at the first request for payment.

So there is no reward here, and we say so up front instead of discovering it together afterwards. What we offer is a real answer within the times set out above and, if you want it, public credit for the finding. If a rewards programme ever does exist, it will be written on this page with its own rules.