Skip to content
Offline Protocol logo Offline Protocol
Connect and sync
Mesh networking Five transports, multi-hop relay, automatic failover Offline identity Device-owned keys, verified device-to-device, bound to accounts Edge sync Edge-native shared state that converges without a server Offline telemetry One opt-in stream, identifiers scrubbed by default
Invoke
Service discovery Advertise, discover, and invoke with no server or DNS Capability Exchange Evidence-based routing across nearby, gateway, and hosted providers Coming soon
Get started
Start building Create a project, get an API key, and watch your devices come online in the developer dashboard. Open the dashboard →
One stack for transport, identity, discovery, data, and execution →
Device makers
Embedded and OEM platforms The leaf profile on constrained silicon, integrated once beside your radio stack Robotics and autonomous systems Swarm coordination past GPS denial and lost links AI agents and edge intelligence Peer-to-peer agent discovery and invocation Agriculture Equipment and sensors beyond rural coverage
Operators
Logistics and field operations Yards, ports, corridors, and linehaul dead zones Energy, utilities, and industrial sites Metering, gateway continuity, and crews off-grid Public sector and distributed sites Coordination through outages and blackouts Live events, venues, and ticketing Crowd-scale connectivity and ticket checks at the gate
Deployed today
Customer stories Read how teams use Offline Protocol to keep their operations running when the network goes down. Read the stories →
Scope an evaluation: one workflow, agreed criteria, 4 to 16 weeks →
Build
Quickstart Install, initialize, and send a message with no server Live demo Watch the SDK pick a transport, in your browser Offline Protocol CLI Log in, wire a project, and add packages from the terminal MCP server Local or hosted, for Claude Code, Codex, Cursor, and more
Reference
Documentation Guides and technical reference API reference TypeScript API over the Rust core Roadmap Shipped, in development, and exploring Security Encryption, identity, and disclosure Service status Live availability and incidents
Agentic development
Build with agents Claude Code, Codex, Cursor, Gemini CLI, VS Code with Copilot, and other MCP clients read the real SDK guidance and scaffold your project. npx -y @offline-protocol/cli mcp serve Connect over MCP →
Ship the mesh in an afternoon. Start with the quickstart →
Pricing
Company
About Who is building it and who backs it Blog Technical and non-technical writing from the team Changelog Every SDK release, newest first Careers Build the network with us Shop Hardware relays and mesh radios
Guides
Glossary Offline and mesh networking terms, defined What is offline mesh networking? The core concept in plain language BLE mesh vs Thread vs Matter How the standards compare Offline-first architecture Designing for no connectivity Compare overview Offline Protocol vs the alternatives
Learn more
Blog What we are shipping, how it works, and where it is being used. Read the blog →
New to offline mesh networking? Start with the glossary →
Docs Start building

Legal

Security and responsible disclosure

Effective September 29, 2026. Last updated September 29, 2026.

We want to hear about security problems in anything Offline Protocol operates or publishes. This page explains how to report one, what we commit to, and the safe harbor we give good-faith researchers.

On this page
  1. 1. Report a vulnerability
  2. 2. What you can expect from us
  3. 3. Scope
  4. 4. Rules of engagement
  5. 5. Safe harbor
  6. 6. How we protect the Services
  7. 7. Security incidents affecting customers

1. Report a vulnerability

Email security@offlineprotocol.com. This address is for security and vulnerability reports only. Please do not report vulnerabilities in public GitHub issues or on social media.

Include what you can of the following:

  • The affected product, service, URL, package, or version, and the commit or release if you know it
  • A description of the issue and the impact you have assessed
  • Steps to reproduce, or a proof of concept
  • Whether you encountered anyone else’s data
  • Any fix you would suggest, and how you would like to be credited

Our security contact is also published in /.well-known/security.txt. If your report contains sensitive details, say so in your first email and we will agree a secure way to share them.

2. What you can expect from us

  • Acknowledgment within 48 hours of your report.
  • An initial assessment and a remediation timeline within 7 days.
  • Updates as we work on a fix, and a note when it ships.
  • Credit in the release notes or advisory, unless you prefer to stay anonymous.

We do not currently run a paid bug bounty program.

3. Scope

3.1 In scope

  • The developer portal at dev.offlineprotocol.com, including sign-in, organizations, API keys, billing screens, and CLI sign-in approval
  • Hosted APIs at api.offlineprotocol.com, including OfflineID, the relay, telemetry ingestion, and Proof of Location
  • The hosted MCP server at mcp.offlineprotocol.com
  • The Offline Protocol CLI (npm package @offline-protocol/cli) and its local credential handling
  • The Offline Protocol SDK and its published packages, including cryptography, identity, and transport flaws
  • The website at www.offlineprotocol.com and the documentation

3.2 Out of scope

  • Denial-of-service or load testing against shared infrastructure (describe the attack instead and we will assess it)
  • Denial of service that requires physical proximity, such as Bluetooth LE range
  • Social engineering, phishing, or physical attacks against our staff, offices, or customers
  • Issues in third-party services we use (report those to the vendor), unless our configuration causes the issue
  • Missing security headers or best-practice findings with no demonstrated impact
  • Issues that affect only development dependencies that are not shipped
  • Apps built on Offline Protocol by other companies, and relays or gateways operated by others

The Fernweh and MINE apps are operated by Offline Protocol, Inc. and reports about them are welcome at the same address.

4. Rules of engagement

To be covered by the safe harbor below, please:

  • Test only against accounts, organizations, applications, devices, and data that you own or have explicit permission to test. Create your own free developer account for testing hosted services.
  • Access, change, or keep only the data you need to demonstrate the issue. Stop as soon as you confirm it, and tell us if you encountered anyone else’s data. Delete it once the report is resolved.
  • Do not degrade the Services for others: no volumetric, load, or denial-of-service testing, and no spam through the relay or through sign-in codes.
  • Do not submit false Proof of Location data to the public testnet contract beyond what is needed to demonstrate an issue, since on-chain records cannot be deleted.
  • Give us reasonable time to fix the issue before you disclose it. The default is 90 days from our acknowledgment. If you plan to publish sooner, tell us and we will agree a timeline together.
  • Do not demand payment. A report conditioned on payment is not a good-faith disclosure.

5. Safe harbor

If you research and report in good faith under this policy, Offline Protocol, Inc. considers your research authorized. We will not bring or support civil or criminal action against you, or report you to law enforcement, for accidental, good-faith violations of this policy. We waive any claim under our terms of service or acceptable use policy that would otherwise prohibit the testing this policy covers, and any anti-circumvention claim for circumventing technical measures in our software during that research. If a third party brings action against you and you complied with this policy, we will make it known that your research was authorized.

This safe harbor covers only claims by Offline Protocol, Inc. It cannot bind third parties, such as a company that built an app on our SDK, an independently operated relay, or a cloud provider we use. It is not permission to break the law. If you are unsure whether a test is covered, email us before you run it.

6. How we protect the Services

The measures we apply to personal data we process for customers are listed in Annex 2 of the data processing addendum. In short:

  • Mesh traffic between devices is protected by the SDK’s MLS (RFC 9420) sessions, whose private keys are generated and held on the device.
  • Every connection to the portal, hosted APIs, and hosted MCP server uses TLS.
  • Portal sign-in uses one-time email codes. Application API keys can be revoked, and keys created for the CLI are revoked when you log out of the CLI.
  • Access to production systems is limited to personnel who need it for their role.
  • Payment card details are entered on Stripe-hosted pages and never reach our servers.

For the protocol’s security design, see the security overview. Current service status is published at status.offlineprotocol.com.

7. Security incidents affecting customers

If we confirm a personal data breach affecting personal data we process on a customer’s behalf, we notify the affected customer without undue delay, as set out in the data processing addendum. If you believe your API key or account has been compromised, revoke the key in the portal and email security@offlineprotocol.com.

Questions about this document, privacy requests, and anything else policy related: email legal@offlineprotocol.com. Security vulnerabilities: security@offlineprotocol.com. All of our legal documents are listed on the legal page.

Offline Protocol

The coordination layer for physical systems.

© 2026 Offline Protocol, Inc.

Platform

The platform Mesh Identity Edge sync Telemetry Discovery Embedded

Solutions

RoboticsAI agentsAgricultureLogisticsEnergyPublic sectorEvents and ticketing Stories

Developers

Developer portal Quickstart Live demo CLI MCP server Documentation API reference Roadmap Security Pricing

Resources

Glossary Compare Blog Changelog The network Ecosystem

Company

About Careers Contact Shop Terms Privacy Developer terms Legal

We use privacy-friendly analytics to understand what's useful and improve the site. Nothing is collected until you allow it. See our privacy policy.

Privacy preferences

Choose what this site may use. You can change this anytime from the privacy policy. Nothing here is shared with advertisers or used to track you across other sites.

Essentiali
Always on

Remembers your theme and this consent choice, in your browser only. No analytics, no tracking.

Product analyticsPostHogi

Helps us see which content and calls-to-action are useful. On by default. Turn it off here anytime.