Skip to content

Latest commit

 

History

History
58 lines (45 loc) · 2.27 KB

File metadata and controls

58 lines (45 loc) · 2.27 KB

Security Policy

Important

Found a vulnerability? Please email security@ripplemail.de — do not open a public issue.

We take the security of our project seriously and appreciate your efforts to responsibly disclose vulnerabilities.


Reporting a vulnerability

If you discover a security vulnerability, please help us keep users safe by following these steps:

  1. Do not open a public issue.
  2. Email us at security@ripplemail.de with:
    • A description of the vulnerability
    • Steps to reproduce (proof of concept, if possible).
    • Potential impact
  3. We will respond within 72 hours.
  4. We will provide updates as we work to resolve the issue and may request additional information.

What counts as a security vulnerability?

Please report things that could put users, data, or systems at risk. Examples include (but aren't limited to):

  • Account takeover or authentication bypass
  • Access to another user's email or data
  • Remote code execution (e.g., XSS, RCE)
  • Leaking sensitive information (emails, passwords, tokens, etc.)
  • Breaking encryption or transport security (e.g., TLS issues)

You don't need to report:

  • Typos, styling issues, or UX bugs
  • Denial-of-service (DoS) or spam/flooding
  • Social engineering attacks
  • Vulnerabilities in third-party dependencies we don't control (though letting us know about them is appreciated if they impact us)

Scope

In scope:

  • Our official code and services under *.ripplemail.de
  • The Ripple Mail clients and APIs

Out of scope:

  • DoS/spam/flooding attacks
  • Social engineering
  • Stuff outside Ripple Mail's control

Responsible disclosure

  • Please give us up to 90 days to fix the issue before public disclosure.
  • If you'd like credit, we'll happily mention you in our release notes/acknowledgements.
  • Malicious or exploitative use of vulnerabilities is not permitted.
  • We don't have a bug bounty programme, but we'll give you props for helping.

Safe Harbour

As long as you're acting in good faith:

  • You won't get in trouble with us for responsibly reporting an issue.
  • Please try not to mess with user data, break services, or cause downtime while testing.

Thank you for helping us keep our project and community safe! 💜