Reporting a vulnerability
If you believe you have found a security issue in ActaSeal, in the standalone verifier, or on this site, please write to security@actaseal.com. A machine-readable version of this contact is published at /.well-known/security.txt.
What to include
What you found, where you found it, and the steps to reproduce it. If the issue concerns a signed artifact, the packet itself is more useful than a description of it. Please do not include third-party data.
What happens next
You will get a reply acknowledging the report. If the issue is confirmed, you will be told what the fix is and when it lands; if it is not, you will be told why. Fixes to the verifier are published in the public repository, so you can check the fix yourself rather than take our word for it.
What this is not
There is no bug bounty and no monetary reward. Reports are handled by one person, not a team, and this page does not promise a response time it cannot keep.
Scope
In scope: actaseal.com, verify.actaseal.com, the published verifier, and the ActaSeal product itself. Out of scope: findings that require access to a deployment you do not control, reports generated by automated scanners without a demonstrated impact, and issues in third-party services listed on the sub-processors page, which should be reported to those providers.