OUTIS ORDER
LEGAL

SECURITY DISCLOSURE

How to report something you found, what happens next, and the part of this process that isn't set up yet.

PROCESS INCOMPLETE
There's no published reporting address for this project yet. That's a gap, it's mine, and this page will carry the address and a key fingerprint the moment there is one. Everything below is written so the process is knowable before it's complete.

How to report, today

If you already have a way to reach me, use it. Send what you found, how to reproduce it, and what you think the impact is. Those three things are the whole report.

If you don't have a way to reach me, this page is the blocker, and standing up a real intake (an address, a published key fingerprint, and somewhere the fingerprint can be checked) is the next thing owed on it. I'd rather write that down than publish an address that bounces.

What happens when a report arrives

I read it. I try to reproduce it, and I tell you whether I could. Then I tell you what I'm doing about it, and roughly when.

I'm not going to publish a response time I can't hold. What I will do is answer, including when the answer is that a fix isn't coming soon, and why.

When a finding changes the design, it gets written up in full, including the part where I had it wrong. Your name goes on it unless you'd rather it didn't.

In scope

  • This website, the web application, and the API.
  • The device firmware, the pairing and claiming flow, and the transport between a device and the server.
  • The audit chain and its verification, including anything that would let a record be altered without detection.
  • The trust anchor and certificate paths, including rotation.

Out of scope

  • Findings that require physical possession of somebody's key and box.
  • Social engineering of me or of anyone else.
  • Denial of service by volume.
  • Scanner output with no demonstrated impact.

What I'll ask of you

  • Don't access, change or delete data that isn't yours. If you can demonstrate access, that's enough. Stop there.
  • Don't run ceremonies against other people's devices.
  • Give me time before publishing. If I'm slow, tell me and publish anyway. A deadline you can't enforce isn't a deadline.

What I'm not claiming

There's no paid bounty program. There's no certification, and no third-party audit of any of this.

One known limit, stated here so it doesn't need discovering: the audit chain detects an entry altered in place, but it can't detect a truncated tail, an omission, or a rewrite from the beginning. Catching those needs a head hash published somewhere outside the system, and there isn't one yet. That's a limitation, not a vulnerability report.

Good faith

I'm not going to come after somebody who reports a problem in good faith and inside the lines above. That's a plain statement of intent, and it isn't a legal safe harbor, because this page isn't a legal document yet. When it is, it'll say so.