Report a Security Issue
Send a reproducible security finding to security@cryptograph.watch.
Bounty program closure
The paid bug bounty program closes on September 30, 2026 at 00:00 UTC. Reports first received on or after that time are not eligible for monetary rewards.
Earlier reports remain subject to the policy and written representations in effect when they were submitted. Approved awards remain unchanged. The September 3, 2026 policy remains available for reference.
Security reporting, coordinated disclosure, and Safe Harbor continue after the paid program closes.
What to send
Include the affected app version and build, reproduction steps, attacker prerequisites, and the impact on users. Identify whether the issue affects a publicly distributed release, a test build, or source code only. Send one finding per report.
Use test accounts you own. Include a minimal proof of concept without real user data, credentials, private keys, or recovery secrets.
Encrypt sensitive reports with our PGP key. Fingerprint: EC3F C7B8 51A5 D177 E1CE 0145 2DD2 2ADA 6389 A1E9.
Scope
Report vulnerabilities in the Cryptograph apps, recovery formats, Cryptograph-operated backend services, and our modifications to public dependencies.
Report Apple platform and third-party service vulnerabilities to their respective maintainers. Do not test denial of service against production infrastructure or use social engineering, physical attacks, or accounts belonging to other people.
Triage and disclosure
- Acknowledge within 3 business days of receipt.
- Initial triage within 7 business days · confirm in-scope, request clarification if needed, assign preliminary severity.
- Status update at 30 days minimum for reports still under active investigation.
- Coordinated disclosure window: 90 days from initial acknowledgement (industry standard). Extensions available by mutual agreement when fix complexity warrants.
- Researcher may publish after the 90-day window expires. We will not retaliate against good-faith disclosure that follows this timeline.
Safe Harbor
Perpetua Labs LLC (the “Company”) commits to the following Safe Harbor for security researchers who comply with this policy. This language is adopted from the disclose.io core terms (MIT-licensed; pulled 2026-05-03).
Safe Harbor, coordinated disclosure, and our non-retaliation commitments do not depend on report validity, severity, monetary eligibility, or payment. A good-faith report that does not qualify for an award still receives acknowledgement and technical review.
Authorization
If you make a good-faith effort to comply with this policy during your security research, we will consider your research to be authorized, we will work with you to understand and resolve the issue quickly, and Perpetua Labs LLC will not recommend or pursue legal action related to your research.
Anti-litigation pledge
To the extent that your security research activities are inconsistent with certain restrictions in our applicable Terms of Service, we waive those restrictions for the limited purpose of permitting security research under this policy. Should legal action be initiated by a third party against you for activities that were conducted in accordance with this policy, we will take steps to make it known that your actions were conducted in compliance with this policy.
ToS waiver
Activities conducted in a manner consistent with this policy are not considered to violate our Terms of Use, our Privacy Policy, the App Store and Apple Developer terms, the US Computer Fraud and Abuse Act (CFAA), the DMCA §1201 anti-circumvention provisions, or analogous computer-misuse laws in other jurisdictions, to the extent of our ability to commit on your behalf.
Good-faith standard
We define “good-faith security research” consistent with the disclose.io Good Faith Security Research standard. In summary, you act in good faith if you:
- Use only the minimum access necessary to demonstrate the vulnerability.
- Avoid privacy violations, destruction of data, and interruption or degradation of our services. Do not exfiltrate any data beyond a minimal proof-of-concept.
- Use only test accounts you own or have explicit permission from the account-holder to test against.
- Do not use social engineering, phishing, or physical attacks against Perpetua Labs employees or infrastructure.
- Disclose the vulnerability privately to security@cryptograph.watch and provide us a reasonable time to respond before any public disclosure (see Triage and disclosure timeline).
- Do not exploit the vulnerability for any reason beyond verifying its existence.
Source: disclose.io core terms, MIT-licensed. Pulled 2026-05-03 from github.com/disclose/diodb. Adapted with Perpetua Labs LLC named as the committing entity and Cryptograph as the named product. Material public-policy revisions are gated on security and legal review before publication.
Policy version 3.0. Effective September 30, 2026 at 00:00 UTC.