Vulnerability Disclosure Policy
Security contact: security@lake8.dev
lake8.dev is committed to working with security researchers to verify and address potential vulnerabilities responsibly.
Reporting a Vulnerability
Section titled “Reporting a Vulnerability”Send reports to: security@lake8.dev
Please include:
- Description of the vulnerability
- Steps to reproduce
- Potential impact
- Your contact information (optional)
Encrypted reports are supported.
Public key: cryptin.lake8.dev/security.asc
Fingerprint B35B D267 08ED 3BB6 DCBF D68A D535 58E2 1111 9C4FKey ID 0xD53558E211119C4FType RSA 4096, sign + encrypt subkeyUID Crypt-in Security (lake8.dev vulnerability disclosure) <security@lake8.dev>Valid until 2028-07-27curl -sO https://cryptin.lake8.dev/security.ascgpg --show-keys security.asc # check the fingerprint above BEFORE importinggpg --import security.ascVerify the fingerprint against this page over a channel you already trust. A key served from the same host as the policy that describes it proves nothing on its own.
Our Commitments
Section titled “Our Commitments”- Acknowledge receipt within 72 hours
- Assess and communicate severity within 14 days
- Fix confirmed vulnerabilities within 90 days
- Credit reporters in release notes (if desired)
- Safe harbor — we will not pursue legal action against researchers acting in good faith
In scope:
- Crypt-in firmware (ESP32-S3)
- License server (
license.lake8.dev) .crinfile format implementation- HID protocol implementation
Out of scope:
- Physical attacks requiring chip-level equipment
- Attacks requiring prior compromise of the host system
- Social engineering
Supported Versions
Section titled “Supported Versions”lake8.dev commits to security support for a minimum of 5 years from the date of first commercial release.