Security

The Hall of Fame.

Most companies patch a vulnerability quietly and hope nobody notices it existed. We think the people who find our mistakes deserve the opposite — permanent, public credit, not a buried changelog line.

Why this page exists

Credit means more than a bounty we can't yet afford.

We don't run a large cash bug bounty program. What we can offer instead is real: a permanent public credit on this page, and a genuine, specific reference from us for your portfolio — the kind of recommendation that actually helps a security researcher's career, written by people who watched you find something real.

Not hidden in a private disclosure inbox. Not quietly folded into a changelog. Named, here, for as long as this site exists.

How it works

Report it. We fix it. You get named.

Report privately first

Email [email protected] with what you found and how to reproduce it. We read every message and will confirm receipt.

Give us a real chance to fix it

We ask for reasonable time to investigate and ship a fix before any public disclosure. We will keep you updated on progress, not go silent.

Stay inside the vault, not other people's

Test against your own device and data. Do not attempt to access, modify, or exfiltrate another user's vault, even to prove a point — that crosses from research into the exact harm this architecture exists to prevent.

You get credited, not ignored

Every confirmed, responsibly disclosed vulnerability earns a permanent entry below once the fix has shipped — your name or handle, what class of issue it was, and the date it was resolved.

Full contact details and our PGP key for encrypted reports are on the Contact page, and at /.well-known/security.txt.

The list

Confirmed reports.

Nobody's here yet.

Prevon is in private beta, and no vulnerability report has been confirmed and fixed yet. The moment one is, this space becomes the first entry — permanently, not quietly removed once the news cycle passes.