Poftim

Vulnerability disclosure

Report a security issue

Send reports affecting poftim.app, its signalling or relay services, or the QRCABLE/1 transfer protocol through the security report form.

Include the affected component, clear reproduction steps, the security impact, relevant logs or screenshots with secrets removed, and a safe way to contact you. Please do not include live pairing links, private files, decryption keys or another person’s personal information.

Scope

What to report

In scope
poftim.app, the browser application, session API, WebSocket signalling, dedicated TURN relay configuration and the documented transfer protocol.
High priority
Reading or altering file contents, stealing pairing or session keys, joining a session without the QR secret, bypassing one-time pairing, or exposing session credentials in logs.
Usually out of scope
Self-XSS, obsolete browsers, social engineering, findings requiring a compromised device or extension, missing headers without demonstrated impact, and denial-of-service without a safe proof.

Testing boundaries

Protect other people and the service

  • Use only your own devices, accounts and filesRequired
  • Do not access, change or retain another person’s dataRequired
  • Do not run high-volume automation or denial-of-service testsRequired
  • Do not test physical security or social engineeringRequired
  • Stop if testing may affect another user or systemRequired

This policy describes a reporting channel. It does not grant permission to access data or systems that you do not own or otherwise have explicit authority to test.

Process

Coordinated disclosure

We aim to acknowledge a useful report within seven calendar days, reproduce and assess it, and keep the reporter informed when there is material progress. Resolution time depends on severity and complexity.

Please allow a reasonable remediation period before publishing technical details. Agree a disclosure date with us where possible. If a report is a duplicate or not reproducible, we will explain that conclusion.

There is currently no paid bug-bounty programme. With permission, validated reporters may be credited after remediation.

Read the security architecture Send a report