Last updated 2026-07-01
Reporting
Send reports to security@synthesiscyber.app or through the form in our Trust Center. Include reproduction steps, affected endpoints, and any proof of concept. Encrypt the report with our published PGP key if it contains sensitive detail.
Our commitments
- We acknowledge within 2 business days and give an initial assessment within 7.
- We keep you updated at least every 14 days until resolution.
- We will not pursue legal action against research conducted in good faith under this policy.
- We credit reporters in our Security Updates log unless you prefer to remain anonymous.
Rules
- Test only against accounts you control. Do not access, modify, or exfiltrate other users' data.
- No denial of service, spam, social engineering of staff or users, or physical attacks.
- Give us reasonable time to remediate before public disclosure — 90 days unless we agree otherwise.
Out of scope
Missing best-practice headers with no demonstrated impact, reports from automated scanners without validation, issues requiring a compromised device or a rooted browser extension, and social engineering findings are generally out of scope.