Vulnerability Disclosure Policy
Last updated: 2026-06-11
Our commitment
We take the security of SealedSpace and our users’ data seriously. If you believe you’ve found a security vulnerability, we want to hear about it and will work with you to understand and resolve it quickly.
How to report
- Email: security@sealedspace.com
- Please include: a description of the issue, steps to reproduce (proof-of-concept if possible), affected component/URL, and your assessment of impact.
Our promise to you (Safe Harbor)
If you make a good-faith effort to comply with this policy during your research, we will:
- Consider your research authorized and will not pursue or support legal action against you.
- Work with you to understand and resolve the issue promptly.
- Acknowledge your contribution (with your permission) once resolved.
Scope
In scope: the SealedSpace web app, API, and desktop/mobile apps, and the
agent/MCP surface — the /agent/* endpoints, the agent scope guard and
device-link/claim flow, and the @sealedspace/mcp client.
Out of scope: third-party services (AWS, Oracle Cloud, Firebase, Anthropic / Claude Code — report to them directly), social engineering, physical attacks, denial-of-service/volumetric testing, and reports from automated scanners without a demonstrated vulnerability.
Rules of engagement
- Do not access, modify, or delete data that isn’t yours; use test accounts.
- Do not run denial-of-service tests or degrade service for others.
- Do not publicly disclose before we’ve had a reasonable chance to fix (see timelines).
- Respect privacy; if you encounter user data, stop and report it.
Our response targets
| Stage | Target |
|---|---|
| Acknowledge receipt | within 2 business days |
| Initial triage / severity assessment | within 5 business days |
| Status updates | at least every 10 business days |
| Coordinated disclosure | by mutual agreement after a fix ships |
These are good-faith targets, not contractual commitments — complex issues may take longer, and we’ll keep you informed if they do.
Severity & prioritization
We triage by impact, prioritizing anything that could undermine the zero-knowledge model (e.g. a path to server-side plaintext access), authentication/authorization bypass, or account takeover.