Security and Vulnerability Disclosure
Coordinated disclosure
We welcome clear, good-faith reports that help us protect Conduital and its users. This policy explains what you may test, what is off-limits, and how to send us a useful report.
- Report
- greg@conduital.com
- Acknowledgment target
- 7 calendar days
- Disclosure window
- Up to 90 days
Report a vulnerability
Email greg@conduital.com with the subject Conduital security report. Please include:
- The affected URL, endpoint, application version, or installer version.
- A concise description of the issue and its likely security impact.
- Reproduction steps using the smallest safe proof of concept possible.
- Any relevant request and response details, screenshots, or logs with secrets and personal data removed.
- Your preferred contact information and any planned disclosure date.
Do not include credentials, license keys, personal data, or other sensitive material unless it is strictly necessary to explain the issue. Ask first if you believe encrypted delivery is necessary; no public encryption key is currently advertised.
Scope
The following Conduital-controlled surfaces are in scope:
conduital.comand its public web endpoints.- The current public Conduital Windows application and installer artifacts distributed directly by Conduital.
The following are out of scope:
- Third-party services and infrastructure, including Gumroad, Vercel, Cloudflare, Stripe, Resend, Kit/ConvertKit, and analytics providers.
- Accounts, devices, workspaces, files, or data that you do not own or have explicit permission to test.
- Previously reported issues that are already being remediated, unless you have material new evidence.
Safe-testing boundaries
Research must use your own accounts, devices, and data. You must not:
- Access, retain, alter, delete, or disclose another person's data.
- Perform denial-of-service, load, stress, or other testing that could degrade availability.
- Use credential stuffing, password spraying, brute force, phishing, social engineering, spam, or malware.
- Attempt payment fraud, interfere with fulfillment, or generate real transactions without authorization.
- Establish persistence, move laterally, or exploit beyond the minimum needed to demonstrate impact.
- Test employees, contractors, physical locations, or any third-party provider.
If you encounter personal data, credentials, or evidence of active compromise, stop testing, preserve only the minimum evidence needed, and report it immediately.
Good-faith research
We consider research conducted in good faith and consistent with this policy to be authorized. We will not initiate legal action solely for an accidental, good-faith violation of this policy. This authorization does not extend to third-party systems, violations of applicable law, or actions that create avoidable harm. If you are unsure whether a test is permitted, contact us before proceeding.
What to expect
We aim to acknowledge a complete report within seven calendar days and will share material updates when practical. These are targets, not guarantees. Remediation timing depends on severity, complexity, and whether the issue is being actively exploited.
Please coordinate public disclosure with us. Unless we agree to another timeline, allow up to 90 days after a complete report for investigation and remediation. We may ask for more time when a fix depends on a third party or a safe release cannot reasonably be completed within that period.
No bounty promise
This is a vulnerability disclosure policy, not a bug-bounty program. We do not promise payment, rewards, reimbursement, or other compensation. Any bounty or paid engagement must be agreed in writing before the work begins.