Responsible Disclosure
Responsible Disclosure
If you believe you have found a security vulnerability in Squillo, report it to us. This page explains how to reach us, what is in scope, what we commit to, and what to expect after you report.
How to report
Email [email protected] with your finding. A useful report includes:
- what you found, and where — a URL on squillo.com, or the Squillo OS client and its version;
- steps to reproduce it;
- what you believe the impact is;
- how we can reach you for follow-up.
Include enough detail in the first message for us to reproduce the issue.
Scope
In scope:
- squillo.com — this website;
- the Squillo OS client applications we distribute.
Out of scope: services we do not operate, even where Squillo integrates with them. If you find a vulnerability in a third-party service, report it to that service's operator.
Safe harbor
We will not pursue or support legal action against you for security research conducted in good faith. Good faith means:
- you make a reasonable effort to avoid violating anyone's privacy, destroying data, or degrading the service;
- you do not access, modify, or keep data that is not yours — if a proof of concept exposes someone else's data, you stop and tell us;
- you give us a reasonable opportunity to fix the issue before you disclose it publicly.
What to expect from us
We will acknowledge your report within 5 business days.
We do not run a bug bounty program and do not offer monetary rewards for vulnerability reports.
Encryption
As of 2026-09-16, no encryption key is published for [email protected], so email to that address is not end-to-end encrypted. A key is forthcoming; when it ships, it will be published here and referenced from security.txt. Until then, include only the details the report needs.
Machine-readable policy
This policy is also published in machine-readable form at /.well-known/security.txt (RFC 9116).
Last verified: 2026-09-16
