Security
Reporting a vulnerability
Send it to info@termiyo.com. Everything below is what happens next.
In scope
The Termiyo desktop application on macOS, Windows and Linux; the sync server and its API; and termiyo.com itself.
What we care about most, in order: anything that exposes vault contents without the master password, anything that lets a compromised renderer reach the network or the filesystem, anything that weakens host key verification, and anything that causes credentials to be written unencrypted to disk or to a log.
Out of scope
Findings that require an attacker to already have your unlocked machine and your master password. Missing security headers on static marketing pages with no authenticated content. Automated scanner output with no demonstrated impact. Denial of service by volume.
Social engineering of our staff or our users, and anything that degrades service for someone else, are not in scope and are not covered by the safe harbour below.
What to expect
We confirm receipt within two working days. Within ten working days we tell you whether we have reproduced it, what severity we think it is, and roughly when we expect a fix.
We do not run a paid bounty programme. We will credit you by name in the release notes unless you would rather we did not.
We ask for ninety days before public disclosure, and we would rather publish together. If we go quiet on you, publish — a vendor who stops answering has forfeited the request.
Safe harbour
If you make a good-faith effort to follow this policy, we will not pursue legal action against you for your research, and we will say so to anyone who asks.
Good faith means: test against your own accounts and your own data, stop as soon as you have confirmed a finding rather than exploring further, never access or modify anyone else’s data, and tell us before you tell anyone else.
Clause 4 of the licence already permits reverse engineering the application to verify its security properties. A tool that asks to hold your credentials has no business being unexaminable.
Machine-readable
This policy is referenced from /.well-known/security.txt, per RFC 9116.