Responsible Disclosure Policy
Cryptex Industries d.o.o. welcomes responsible reports of security issues in Cryptex Vault. At the moment we do not offer a paid bug bounty, but we will do our best to thank researchers and credit them when a fix ships.
1. How to report
Email [email protected]. Do not open a public GitHub issue for security vulnerabilities.
You should receive a first response within 3 working days.
2. What to include
- Short summary of the issue and its impact
- Affected product or surface (web app, extension, desktop client, API, or infrastructure) and version or commit if known
- Step-by-step reproduction with your own test accounts and data only
- Proof of concept (commands, screenshots, or a minimal patch) sufficient to verify the issue
- Any suggested fix (optional)
- How you want to be credited when a fix ships (name, handle, or anonymous)
3. Scope
In scope: Cryptex Vault web application, browser extensions, desktop clients, APIs, and infrastructure operated by Cryptex Industries d.o.o.
Out of scope (non-exhaustive):
- Social engineering, phishing, or physical attacks
- Denial of service, volumetric flooding, or resource exhaustion without a distinct security flaw
- Issues in third-party services we rely on (for example Stripe, email providers, CDNs, browsers, or operating systems) unless Cryptex Vault misuses them in a way that creates a clear vulnerability
- Findings that require prior access to an unlocked device or already-decrypted vault data with no further bypass
- Automated scanner output without a working proof of concept
- Missing recommended security headers or other hardening suggestions that do not demonstrate a real vulnerability
4. Rules of engagement
- Use only accounts and vault data you own or create for testing
- Do not access, modify, or exfiltrate other users' data
- Do not degrade service availability for others
- Stop and report promptly if you encounter sensitive data that is not yours
- Keep vulnerability details private until coordinated disclosure (see below)
5. Safe harbor
If you make a good-faith effort to follow this policy, Cryptex Industries d.o.o. will not pursue legal action against you for researching or reporting a security issue covered by this policy. We consider such research authorized under applicable anti-hacking laws to the extent the activity stays within these rules.
Safe harbor does not cover activity outside this policy, intentional harm, privacy violations, or extortion.
6. Disclosure timeline
Please wait before public disclosure. We aim to fix issues as quickly as we can. Unless we agree otherwise, you may disclose 30 days after your initial report, or earlier once we confirm a fix is available.
7. Recognition
At the moment there is no monetary reward. When a valid issue is fixed, we will credit the reporter as a thank you for their efforts unless they ask to remain anonymous. Duplicate or out-of-scope reports may receive a short reply or none beyond acknowledgment.
8. Contact
Cryptex Industries d.o.o.
[email protected]
Also see our Privacy Policy and Terms of Service.