Skip to content

Vulnerability Disclosure Policy

Security contact: security@lake8.dev

lake8.dev is committed to working with security researchers to verify and address potential vulnerabilities responsibly.

Send reports to: security@lake8.dev

Please include:

  • Description of the vulnerability
  • Steps to reproduce
  • Potential impact
  • Your contact information (optional)

Encrypted reports are supported.

Public key: cryptin.lake8.dev/security.asc

Fingerprint B35B D267 08ED 3BB6 DCBF D68A D535 58E2 1111 9C4F
Key ID 0xD53558E211119C4F
Type RSA 4096, sign + encrypt subkey
UID Crypt-in Security (lake8.dev vulnerability disclosure) <security@lake8.dev>
Valid until 2028-07-27
Terminal window
curl -sO https://cryptin.lake8.dev/security.asc
gpg --show-keys security.asc # check the fingerprint above BEFORE importing
gpg --import security.asc

Verify the fingerprint against this page over a channel you already trust. A key served from the same host as the policy that describes it proves nothing on its own.

  • Acknowledge receipt within 72 hours
  • Assess and communicate severity within 14 days
  • Fix confirmed vulnerabilities within 90 days
  • Credit reporters in release notes (if desired)
  • Safe harbor — we will not pursue legal action against researchers acting in good faith

In scope:

  • Crypt-in firmware (ESP32-S3)
  • License server (license.lake8.dev)
  • .crin file format implementation
  • HID protocol implementation

Out of scope:

  • Physical attacks requiring chip-level equipment
  • Attacks requiring prior compromise of the host system
  • Social engineering

lake8.dev commits to security support for a minimum of 5 years from the date of first commercial release.