1. Report a vulnerability
Email security@offlineprotocol.com. This address is for security and vulnerability reports only. Please do not report vulnerabilities in public GitHub issues or on social media.
Include what you can of the following:
- The affected product, service, URL, package, or version, and the commit or release if you know it
- A description of the issue and the impact you have assessed
- Steps to reproduce, or a proof of concept
- Whether you encountered anyone else’s data
- Any fix you would suggest, and how you would like to be credited
Our security contact is also published in /.well-known/security.txt. If your report contains sensitive details, say so in your first email and we will agree a secure way to share them.
2. What you can expect from us
- Acknowledgment within 48 hours of your report.
- An initial assessment and a remediation timeline within 7 days.
- Updates as we work on a fix, and a note when it ships.
- Credit in the release notes or advisory, unless you prefer to stay anonymous.
We do not currently run a paid bug bounty program.
3. Scope
3.1 In scope
- The developer portal at dev.offlineprotocol.com, including sign-in, organizations, API keys, billing screens, and CLI sign-in approval
- Hosted APIs at api.offlineprotocol.com, including OfflineID, the relay, telemetry ingestion, and Proof of Location
- The hosted MCP server at mcp.offlineprotocol.com
- The Offline Protocol CLI (npm package @offline-protocol/cli) and its local credential handling
- The Offline Protocol SDK and its published packages, including cryptography, identity, and transport flaws
- The website at www.offlineprotocol.com and the documentation
3.2 Out of scope
- Denial-of-service or load testing against shared infrastructure (describe the attack instead and we will assess it)
- Denial of service that requires physical proximity, such as Bluetooth LE range
- Social engineering, phishing, or physical attacks against our staff, offices, or customers
- Issues in third-party services we use (report those to the vendor), unless our configuration causes the issue
- Missing security headers or best-practice findings with no demonstrated impact
- Issues that affect only development dependencies that are not shipped
- Apps built on Offline Protocol by other companies, and relays or gateways operated by others
The Fernweh and MINE apps are operated by Offline Protocol, Inc. and reports about them are welcome at the same address.
4. Rules of engagement
To be covered by the safe harbor below, please:
- Test only against accounts, organizations, applications, devices, and data that you own or have explicit permission to test. Create your own free developer account for testing hosted services.
- Access, change, or keep only the data you need to demonstrate the issue. Stop as soon as you confirm it, and tell us if you encountered anyone else’s data. Delete it once the report is resolved.
- Do not degrade the Services for others: no volumetric, load, or denial-of-service testing, and no spam through the relay or through sign-in codes.
- Do not submit false Proof of Location data to the public testnet contract beyond what is needed to demonstrate an issue, since on-chain records cannot be deleted.
- Give us reasonable time to fix the issue before you disclose it. The default is 90 days from our acknowledgment. If you plan to publish sooner, tell us and we will agree a timeline together.
- Do not demand payment. A report conditioned on payment is not a good-faith disclosure.
5. Safe harbor
If you research and report in good faith under this policy, Offline Protocol, Inc. considers your research authorized. We will not bring or support civil or criminal action against you, or report you to law enforcement, for accidental, good-faith violations of this policy. We waive any claim under our terms of service or acceptable use policy that would otherwise prohibit the testing this policy covers, and any anti-circumvention claim for circumventing technical measures in our software during that research. If a third party brings action against you and you complied with this policy, we will make it known that your research was authorized.
This safe harbor covers only claims by Offline Protocol, Inc. It cannot bind third parties, such as a company that built an app on our SDK, an independently operated relay, or a cloud provider we use. It is not permission to break the law. If you are unsure whether a test is covered, email us before you run it.
6. How we protect the Services
The measures we apply to personal data we process for customers are listed in Annex 2 of the data processing addendum. In short:
- Mesh traffic between devices is protected by the SDK’s MLS (RFC 9420) sessions, whose private keys are generated and held on the device.
- Every connection to the portal, hosted APIs, and hosted MCP server uses TLS.
- Portal sign-in uses one-time email codes. Application API keys can be revoked, and keys created for the CLI are revoked when you log out of the CLI.
- Access to production systems is limited to personnel who need it for their role.
- Payment card details are entered on Stripe-hosted pages and never reach our servers.
For the protocol’s security design, see the security overview. Current service status is published at status.offlineprotocol.com.
7. Security incidents affecting customers
If we confirm a personal data breach affecting personal data we process on a customer’s behalf, we notify the affected customer without undue delay, as set out in the data processing addendum. If you believe your API key or account has been compromised, revoke the key in the portal and email security@offlineprotocol.com.
Questions about this document, privacy requests, and anything else policy related: email legal@offlineprotocol.com. Security vulnerabilities: security@offlineprotocol.com. All of our legal documents are listed on the legal page.