HOW TO REACH US
Email security@safehanded.com. For sensitive reports, ask for our PGP key in your first message and we'll share it. Our machine-readable policy lives at /.well-known/security.txt.
Our commitment to you
If you make a good-faith effort to follow this policy while researching, we will:
- Not pursue or support legal action against you for your research.
- Work with you to understand and resolve the issue quickly, and acknowledge your report.
- Credit you when a fix ships, if you'd like the credit, or keep you anonymous if you'd prefer.
We don't currently run a paid bug-bounty programme. We're a young company and would rather be honest about that than imply a reward we can't guarantee. That may change; recognition is offered now.
How to report
- Email security@safehanded.com with enough detail for us to reproduce: what you found, where, and the steps.
- Include the impact you believe it has, and any proof-of-concept, kept minimal.
- Give us a reasonable window to investigate and fix before any public disclosure. We'll keep you updated on progress.
In scope
- The SafeHanded web application and API.
- The public handover and link-checker pages.
- The cryptographic design, in particular anything that would let our servers, staff or a link-holder read a secret they shouldn't.
Out of scope
Please don't do anything that harms our users or their data. In particular, the following are out of scope and may not be tested against production:
- Denial-of-service, volumetric or brute-force testing, and physical or social-engineering attacks against our staff or customers.
- Reports from automated scanners without a demonstrated, exploitable impact.
- Accessing, modifying or exfiltrating data that isn't yours. Use your own test tenant and test data.
- Findings that require a compromised device, a malicious browser extension, or a rooted OS, though we're still interested in hearing about them.
Verify things yourself first
Some of what a security researcher would want to check, you can check without contacting us. Our audit log ships with a standalone, dependency-free verifier so you can prove the hash chain wasn't tampered with, and the security page documents the encryption design and the automated invariant that fails our build if secret material ever reaches the server or logs.
Contact: security@safehanded.com · Policy: /.well-known/security.txt · Harman AJ Ltd