Security and vulnerability reporting

This page is a draft, published so the shape of a reporting channel exists before anyone needs it. The address below is a placeholder Matt has not yet confirmed: do not rely on it to reach anyone until this notice is gone.

What this covers

Appro's own applications, this website, and ApproKernel, the clean-room governance toolkit Appro builds its agents on and publishes for others to use. If you are unsure whether something you found belongs here, report it anyway and we will redirect it if it does not.

How to report

Describe the issue, name the affected application or repository and its version, give the steps to reproduce it, and say what you think its impact is. A report that lets us reproduce the problem is worth more than one that only asserts it.

Do not include the vulnerable material itself, a working exploit, or anything that could cause harm if this message reached the wrong person, until the address above is confirmed as the real one. Once it is, this notice comes down.

What to expect

This channel has not yet handled a report, so no response time is promised here. Once the address is confirmed, this section will state what Appro commits to: an acknowledgement, a way to track the report, and no requirement that you disclose your identity to be heard.

Coordinated disclosure

Please do not open a public issue, post the finding, or otherwise disclose it before we have had a reasonable chance to respond. We do not offer a bounty. We do commit to not pursuing legal action against a report made in good faith, through this channel, that does not access or alter data beyond what is needed to demonstrate the issue.

A question about this notice, not a vulnerability.

An email starts it, and it is answered quickly, by the person who would do the work.

hello@appro-app.com