Security and Vulnerability Disclosure

Coordinated disclosure

We welcome clear, good-faith reports that help us protect Conduital and its users. This policy explains what you may test, what is off-limits, and how to send us a useful report.

Acknowledgment target
7 calendar days
Disclosure window
Up to 90 days

Report a vulnerability

Email greg@conduital.com with the subject Conduital security report. Please include:

  • The affected URL, endpoint, application version, or installer version.
  • A concise description of the issue and its likely security impact.
  • Reproduction steps using the smallest safe proof of concept possible.
  • Any relevant request and response details, screenshots, or logs with secrets and personal data removed.
  • Your preferred contact information and any planned disclosure date.

Do not include credentials, license keys, personal data, or other sensitive material unless it is strictly necessary to explain the issue. Ask first if you believe encrypted delivery is necessary; no public encryption key is currently advertised.

Scope

The following Conduital-controlled surfaces are in scope:

  • conduital.com and its public web endpoints.
  • The current public Conduital Windows application and installer artifacts distributed directly by Conduital.

The following are out of scope:

  • Third-party services and infrastructure, including Gumroad, Vercel, Cloudflare, Stripe, Resend, Kit/ConvertKit, and analytics providers.
  • Accounts, devices, workspaces, files, or data that you do not own or have explicit permission to test.
  • Previously reported issues that are already being remediated, unless you have material new evidence.

Safe-testing boundaries

Research must use your own accounts, devices, and data. You must not:

  • Access, retain, alter, delete, or disclose another person's data.
  • Perform denial-of-service, load, stress, or other testing that could degrade availability.
  • Use credential stuffing, password spraying, brute force, phishing, social engineering, spam, or malware.
  • Attempt payment fraud, interfere with fulfillment, or generate real transactions without authorization.
  • Establish persistence, move laterally, or exploit beyond the minimum needed to demonstrate impact.
  • Test employees, contractors, physical locations, or any third-party provider.

If you encounter personal data, credentials, or evidence of active compromise, stop testing, preserve only the minimum evidence needed, and report it immediately.

Good-faith research

We consider research conducted in good faith and consistent with this policy to be authorized. We will not initiate legal action solely for an accidental, good-faith violation of this policy. This authorization does not extend to third-party systems, violations of applicable law, or actions that create avoidable harm. If you are unsure whether a test is permitted, contact us before proceeding.

What to expect

We aim to acknowledge a complete report within seven calendar days and will share material updates when practical. These are targets, not guarantees. Remediation timing depends on severity, complexity, and whether the issue is being actively exploited.

Please coordinate public disclosure with us. Unless we agree to another timeline, allow up to 90 days after a complete report for investigation and remediation. We may ask for more time when a fix depends on a third party or a safe release cannot reasonably be completed within that period.

No bounty promise

This is a vulnerability disclosure policy, not a bug-bounty program. We do not promise payment, rewards, reimbursement, or other compensation. Any bounty or paid engagement must be agreed in writing before the work begins.

Last updated: August 2, 2026. Machine-readable contact information is available at /.well-known/security.txt.