Vulnerability disclosure
Report a security issue
Send reports affecting poftim.app, its signalling or relay services, or the QRCABLE/1 transfer protocol through the security report form.
Include the affected component, clear reproduction steps, the security impact, relevant logs or screenshots with secrets removed, and a safe way to contact you. Please do not include live pairing links, private files, decryption keys or another person’s personal information.
Scope
What to report
Testing boundaries
Protect other people and the service
- Use only your own devices, accounts and filesRequired
- Do not access, change or retain another person’s dataRequired
- Do not run high-volume automation or denial-of-service testsRequired
- Do not test physical security or social engineeringRequired
- Stop if testing may affect another user or systemRequired
This policy describes a reporting channel. It does not grant permission to access data or systems that you do not own or otherwise have explicit authority to test.
Process
Coordinated disclosure
We aim to acknowledge a useful report within seven calendar days, reproduce and assess it, and keep the reporter informed when there is material progress. Resolution time depends on severity and complexity.
Please allow a reasonable remediation period before publishing technical details. Agree a disclosure date with us where possible. If a report is a duplicate or not reproducible, we will explain that conclusion.
There is currently no paid bug-bounty programme. With permission, validated reporters may be credited after remediation.