Trust

Found a security issue? Tell us directly.

This is a safe-harbor disclosure policy, not a bounty program: we do not pay for reports today, and we will not pursue legal action against good-faith research conducted under these terms.

Last updated 2026-09-18.

Scope

In scope: the skarn binary, the customer portal at account.getskarn.com, the license service API, and getskarn.com. Out of scope: the third-party services we depend on (Cloudflare, Amazon Web Services, GitHub, Paddle, SMTP2GO, Hetzner, HubSpot, Microsoft, Zadarma) - report those to the vendor directly; social engineering, physical attacks, and denial-of-service testing against our production infrastructure.

How to report

Email security@getskarn.com with a description of the issue, the steps to reproduce it, and its impact. We do not publish a PGP key for encrypted reports. Do not open a public GitHub issue for a security finding.

Include, where relevant: the affected command or endpoint, a proof-of-concept (redacted of any real secret you used to demonstrate it), the skarn version or portal timestamp, and your assessment of severity.

What happens after you report

  • An acknowledgment. A person answers you.
  • An initial severity assessment. We tell you whether we can reproduce it and how we are scoping the fix.
  • A fix or mitigation timeline. We tell you the timeline and prioritize by severity: critical issues (remote code execution, secret exposure, authentication bypass) get the fastest turnaround.
  • Credit, if you want it. With your permission, we will name you in the fix's release notes or on this page.
  • No bounty today. We do not run a paid program.

Safe harbor

Security research conducted consistent with this policy is authorized: we will not pursue legal action, and we will not report you to law enforcement, for good-faith testing that (a) stays within the scope above, (b) avoids privacy violations, service disruption, or destruction of data, (c) uses only accounts and data you own or have explicit permission to test, and (d) gives us a reasonable window to fix the issue before any public disclosure. If a third party initiates legal action related to your research and you have complied with this policy, we will state publicly that your research was authorized.

This safe harbor does not cover the third-party services listed under Scope above, which set their own policies.

Coordinated disclosure

We ask for 90 days from our acknowledgment before public disclosure, or until a fix ships, whichever is sooner, and we will tell you as soon as a fix is out so you are not left guessing. If we miss agreed timelines without explanation, disclose on your own schedule - the point of this policy is trust in both directions.