Security disclosure

Found a weakness? Tell us.

SafeHanded is a security product, so we treat vulnerability reports as a gift, not a threat. Here's how to report one and what you can expect from us.

HOW TO REACH US

Email security@safehanded.com. For sensitive reports, ask for our PGP key in your first message and we'll share it. Our machine-readable policy lives at /.well-known/security.txt.

Our commitment to you

If you make a good-faith effort to follow this policy while researching, we will:

We don't currently run a paid bug-bounty programme. We're a young company and would rather be honest about that than imply a reward we can't guarantee. That may change; recognition is offered now.

How to report

  1. Email security@safehanded.com with enough detail for us to reproduce: what you found, where, and the steps.
  2. Include the impact you believe it has, and any proof-of-concept, kept minimal.
  3. Give us a reasonable window to investigate and fix before any public disclosure. We'll keep you updated on progress.

In scope

Out of scope

Please don't do anything that harms our users or their data. In particular, the following are out of scope and may not be tested against production:

Verify things yourself first

Some of what a security researcher would want to check, you can check without contacting us. Our audit log ships with a standalone, dependency-free verifier so you can prove the hash chain wasn't tampered with, and the security page documents the encryption design and the automated invariant that fails our build if secret material ever reaches the server or logs.

Contact: security@safehanded.com · Policy: /.well-known/security.txt · Harman AJ Ltd