Responsible Disclosure
Found something we missed?
Contact
Section titled “Contact”| security@lake8.dev | |
| PGP key | cryptin.lake8.dev/security.asc |
| Fingerprint | B35B D267 08ED 3BB6 DCBF D68A D535 58E2 1111 9C4F |
| Type | RSA 4096, sign + encrypt subkey |
| Valid until | 2028-07-27 |
Encryption is optional. Use it if the report contains anything you would not send in the clear — a working exploit, a memory dump, a customer file.
curl -sO https://cryptin.lake8.dev/security.ascgpg --show-keys security.asc # check the fingerprint above BEFORE importinggpg --import security.ascCheck the fingerprint against the one in this table before you import. A key served over HTTPS is only as trustworthy as the server that served it.
What we commit to
Section titled “What we commit to”- Acknowledge receipt within 7 days
- Assess and communicate severity within 21 days, with a fix timeline
- Fix confirmed vulnerabilities within 90 days
- Credit you in the public report if your finding leads to a fix — by name, or anonymously if you prefer
- Never take legal action against good-faith security research
Good faith means: you did not exfiltrate other people’s data, you did not degrade a service for anyone else, and you gave us a reasonable window before publishing. Within that, you are welcome to write about what you found.
The full policy, including what is in scope and what is not, is in the Vulnerability Disclosure Policy.
If you are a beta participant
Section titled “If you are a beta participant”Beta testers are part of the security program by design — see You are the red team. Start from the August 2026 red team report: it lists what was already tried, what held, and what did not. A finding that reproduces something already published there is still useful, but the interesting ones are the attacks nobody has run yet.
There is no monetary bounty. What there is: your name in the Q1 2027 public launch security report, and a straight answer about what we are going to do with what you found.
Terms of ServicePrivacy PolicySecurity contact: security@lake8.devVulnerability Disclosure Policy
Alcuni contenuti sono stati redatti con il supporto di strumenti di intelligenza artificiale generativa e revisionati dall'autore. Le immagini hardware hanno scopo puramente illustrativo.
Some content was drafted with the support of generative AI tools and reviewed by the author. Hardware images are purely illustrative.
Einige Inhalte wurden mit Unterstützung generativer KI-Werkzeuge verfasst und vom Autor überprüft. Hardware-Abbildungen dienen ausschließlich illustrativen Zwecken.
Algunos contenidos han sido redactados con el apoyo de herramientas de IA generativa y revisados por el autor. Las imágenes de hardware tienen carácter meramente ilustrativo.
In caso di conflitto tra versioni linguistiche, prevale il testo in lingua italiana.