Found something?
Tell us and we will fix it. This page says where to send it, what we will do with it, and what we promise not to do to you.
The machine-readable version is at /.well-known/security.txt.
We will not come after you
If you find a problem while genuinely trying to make this service safer, we will not sue you, report you, or ask anyone else to. That holds even if you end up somewhere you did not expect to be, which happens, because that is what a bug is.
We are asking you to stay inside two lines. Do not access, modify or keep anyone else's data: if you can reach it, that is the finding, and you do not need to prove it by collecting it. Do not degrade the service for other people. If you cannot demonstrate something without crossing either line, write to us and we will set up an account or an environment for you.
We would rather hear about a problem than be right about the boundaries of this paragraph. If you are unsure, ask first.
What we want to hear about
- This site and the dashboard, at
alias.mom - The REST API and the "Sign in with alias" OIDC provider
- The mail path: inbound forwarding, replies through a masked address, and authenticated SMTP submission
- The browser extension
- The source itself, including anything you spot by reading it rather than by running it
A self-hosted instance runs the same code, so a finding there is a finding here. Someone else's misconfiguration of their own instance is theirs.
Anything touching the vault, the blind indexes, the private inbox, or a way to read mail that is not yours goes to the top of the list. Those are the claims this whole product rests on.
What we will probably close
- Missing headers or a TLS configuration nit with no exploit behind it
- Scanner output pasted without a working proof
- Denial of service, volumetric or otherwise
- Social engineering of us or of our users, and anything physical
- Self-inflicted findings that need a compromised device to begin with
Not because they are never real, but because they arrive constantly and almost never are. A working proof of concept moves anything on this list straight back into scope.
Our side of it
- We acknowledge within 3 working days. If you hear nothing, assume the mail went missing and try the second address above.
- We tell you whether we think it is real, and why, within 10 working days.
- We ask for 90 days before you publish, and we will usually be finished long before that. If we are going to miss it we will say so early rather than at the deadline, and if we go quiet the 90 days are yours to use. It is a request, not a condition of the safe harbour above.
- We credit you by whatever name you like, or not at all.
- If the fix touches something we have claimed publicly, it goes in the changelog and, when users were exposed, we say so.
There is no bug bounty. We are small and we would rather say that plainly than waste your afternoon. If you want to be paid for your time, this is not the right target, and no hard feelings.
What we can offer instead, for anything we confirm and fix: your name on this page, and a lifetime premium account on request. Small, and at least it is real.
Nobody yet
Nobody has reported anything. That is a statement about our age, not our code. This list starts the day someone does.
Reporting a user, not a bug
If someone is using an alias to send you something they should not, that goes to abuse, which is handled by different people with a different runbook.