Security

Security matters. If you discover a vulnerability in PrivateStater, please disclose it responsibly.

Translation notice

Some machine translations (e.g., Google Translate, Papago) have been reported to mistranslate parts of this page. For the most accurate information, refer to the original English text.

Reporting a Vulnerability

If you believe you've found a security vulnerability, report it via email. I'll work with you to understand and fix it.

Response Timeline

I aim to acknowledge your report within 48 hours. I'll keep you updated and let you know when it's fixed.

What to Include

Please include the following information in your report:

Scope

The following are in scope for security reports:

Out of Scope

The following are not considered valid security reports:

Prohibited actions

Please avoid the actions below. If testing a vulnerability requires any of them, email me with details and I'll test it myself.

Bug Bounty

PrivateStater is a solo project, so I can't offer monetary rewards right now. If you'd like recognition, I can credit you on the contributors list.

Safe Harbor

I won't take legal action against security researchers who discover and report vulnerabilities in good faith while following these guidelines. Thanks for helping keep things safer.