Reporting a vulnerability to us.
If you have found a security issue in this website, in something we have audited, or in any code we have published, we want to hear about it.
How to report
Email security@inversez.com with enough detail to reproduce the issue. If you would like to encrypt, ask us for a key and we will send one.
We will acknowledge within two working days and give you an assessment within seven. We will keep you updated until it is resolved, and we will credit you publicly if you want the credit.
What we ask
- Give us reasonable time to fix the issue before disclosing it publicly.
- Do not access, modify or delete data belonging to anyone else.
- Do not degrade service for other users: no automated scanning at volume, no denial of service.
- Report issues in contracts we audited to the project first; we are happy to help coordinate.
What we will not do
We will not pursue legal action against anyone who reports in good faith and follows the guidance above. We will not ask you to sign an NDA as a condition of reporting.
Scope
This site, our published code, and any contract listed on our reports register. For third-party services we use, please report to them directly.
No bug bounty yet
We do not currently pay for reports. We would rather say that plainly than imply otherwise. We do credit reporters, and we respond properly to everything we receive.