Reporting vulnerabilities

How to report a security problem in TACENZA privately, what we promise in return, and the rules for testing in good faith.

If you’ve found a security problem in TACENZA, please tell us privately first, so we can fix it before anyone else learns about it. This page explains where to report, what happens next, and the rules for testing. It’s for security vulnerabilities – for abuse by another user, see Report abuse, and for anything else, contact support.

How to report

Report security problems privately through GitHub:

  1. Open github.com/tacenza/releases/security/advisories/new. You can also get there from the tacenza/releases repository under Security › Report a vulnerability.
  2. Describe the problem, what it affects, and how to reproduce it.
  3. Submit the report. Only you and the TACENZA team can see it.

You don’t need to share anything but the problem. The same contact is published in security.txt, at https://chat.tacenza.app/.well-known/security.txt, which also lists the languages we read: English and Danish.

Important

Please don’t report security problems in public issues, on social media or through general support. A private report protects the people who use TACENZA while the problem is fixed.

What happens next

  • We acknowledge reports within 3 working days, and keep you updated until the problem is fixed.
  • We aim to fix critical problems within 14 days, and others within 90 days.
  • We agree a disclosure date with you. Please give us that time before publishing.
  • If you want, we’ll credit you when the fix is published.

There is no paid bug bounty yet.

Testing in good faith

  • Test only against your own accounts.
  • Don’t access other people’s data.
  • Don’t degrade the service for others.
  • Don’t use social engineering or physical attacks.

If you act in good faith and follow this policy, we won’t take legal action against you.

Before you report

Before reporting, check Known limits. Limits listed there, such as the lack of forward secrecy within a key generation or screenshots in a browser, are already known – but if you’ve found a way to make one worse than we describe, we want to hear about it.

Useful background