If you've found a security issue in EcoCloud, we want to hear from you. This page is the canonical policy referenced by our security.txt — it tells you exactly what's in scope, how to report, what we commit to in return, and the safe-harbor terms that protect good-faith research.
Email [email protected] with enough detail for us to reproduce: the affected endpoint or page, a clear description of the issue and its impact, and a minimal proof-of-concept (request/response, steps, or a short script). Encrypt sensitive details if you prefer — ask in your first message and we'll arrange a channel.
Please include a way to contact you for follow-up. If you'd like public credit, say so and tell us the name/handle to use — see acknowledgments below.
Test only against your own workspace, accounts, and agent keys. Never access, modify, or retain data that isn't yours. If you stumble onto someone else's data, stop, and tell us — that itself is a valid report.
We're an early-stage product, but coordinated disclosure deserves a real SLA. Business days, from when your report reaches [email protected]:
| Stage | Target |
|---|---|
| Acknowledge receipt | within 2 business days |
| Triage & initial severity assessment | within 5 business days |
| Progress update cadence until resolved | at least every 7 days |
| Coordinated public disclosure | by mutual agreement, default 90 days after triage |
| Severity | Example | Fix target |
|---|---|---|
| Critical | Auth bypass, cross-workspace data access, RCE, agent-key forgery | ≤ 7 days |
| High | Privilege escalation within a workspace, constitution bypass on writes | ≤ 30 days |
| Medium | Stored XSS in low-privilege view, audit-log integrity gap | ≤ 60 days |
| Low | Info disclosure with limited impact, rate-limit edge cases | best effort |
We don't currently run a paid bug-bounty. Reports are rewarded with public credit and our genuine thanks — we'll be upfront about that rather than imply a payout that doesn't exist.
We support good-faith security research. If you make a good-faith effort to comply with this policy during your research, we will:
"Good faith" means: you stay within scope, you stop at the minimum proof needed, you don't access or destroy others' data, you don't degrade service, and you give us reasonable time to remediate before any public disclosure. If legal action is brought against you by a third party for activity that complied with this policy, we'll make our authorization known.
Researchers who have responsibly disclosed valid issues — with their permission — are credited here. No external disclosures yet. Be the first: a confirmed in-scope report earns a permanent entry on this page.
The machine-readable counterpart of this page lives at /.well-known/security.txt. Separately, EcoCloud audit receipts are signed with an ECDSA P-256 key whose public half is published as a JWKS at /.well-known/flowdesk-signing-key.json — anyone can verify a receipt's signature in the browser with the Web Crypto API. See the verifiable-receipts demo on the showcase, and the Trust & security overview.