Public bounty launches when we can triage fairly. Private disclosures welcomed today.
We take security reports seriously. A public bug-bounty programme opens once there's the staffing to triage inside 48 hours. Until then, please disclose privately. We'll credit you, with your permission, and pay where the policy below says we pay.
If we can’t keep a promise yet, it gets written here first.
How to reach us
One email, one PGP key.
Send reports to security@confinity.com. Include a proof of concept, the affected URL, and any fix you’d suggest. If the report carries somebody's personal data, even inside the proof of concept, tell us first. We'll agree a channel. The PGP key published at /.well-known/pgp-key.txt is a placeholder and won’t decrypt anything, so please don’t rely on it. A real key replaces it before the public programme opens.