← Security & Trust

Vulnerability Disclosure Policy

Last updated: 2026-06-11

Our commitment

We take the security of SealedSpace and our users’ data seriously. If you believe you’ve found a security vulnerability, we want to hear about it and will work with you to understand and resolve it quickly.

How to report

Our promise to you (Safe Harbor)

If you make a good-faith effort to comply with this policy during your research, we will:

Scope

In scope: the SealedSpace web app, API, and desktop/mobile apps, and the agent/MCP surface — the /agent/* endpoints, the agent scope guard and device-link/claim flow, and the @sealedspace/mcp client.

Out of scope: third-party services (AWS, Oracle Cloud, Firebase, Anthropic / Claude Code — report to them directly), social engineering, physical attacks, denial-of-service/volumetric testing, and reports from automated scanners without a demonstrated vulnerability.

Rules of engagement

Our response targets

StageTarget
Acknowledge receiptwithin 2 business days
Initial triage / severity assessmentwithin 5 business days
Status updatesat least every 10 business days
Coordinated disclosureby mutual agreement after a fix ships

These are good-faith targets, not contractual commitments — complex issues may take longer, and we’ll keep you informed if they do.

Severity & prioritization

We triage by impact, prioritizing anything that could undermine the zero-knowledge model (e.g. a path to server-side plaintext access), authentication/authorization bypass, or account takeover.