Found a security issue? Email security@boringaico.com. We welcome good-faith research and won't pursue legal action for testing that follows this policy. We aim to acknowledge reports within three business days.
If you believe you've found a security vulnerability in Boring, please report it privately to security@boringaico.com. Include enough detail for us to reproduce the issue:
Please give us a reasonable opportunity to fix the issue before disclosing it publicly, and don't access, modify, or delete data that isn't yours while testing.
This policy covers the systems we operate:
We consider security research and vulnerability disclosure conducted in good faith under this policy to be authorized. We will not pursue or support legal action against you for such research, provided you:
The following are generally out of scope. Reports limited to these will usually be closed without action:
Boring does not currently run a paid bug-bounty program. We're grateful for responsible disclosure and are happy to publicly credit researchers who report valid issues, if you'd like. A machine-readable version of this policy is available at /.well-known/security.txt.