Report a security issue responsibly
Scope
Security issues in Scrinium's crypto, sync, authentication, or web application are in scope. Please do not test against real user data, and do not publicly disclose before we've had a chance to review and remediate.
What to include
- A clear description of the vulnerability.
- The affected component and version/commit.
- Reproduction steps or proof-of-concept.
- Impact and any suggested mitigation.
Our commitment
- We will acknowledge receipt and keep you updated.
- We will work with you to reach a fix and responsible disclosure.
- We will credit the reporter in our security page (unless you prefer anonymity).
Contact
Email: [email protected]
Legal
We welcome good-faith research and will not pursue action against responsible, non-destructive disclosure. Please do not access other users' data or cause disruption.