Found a security issue? Tell us directly.
This is a safe-harbor disclosure policy, not a bounty program: we do not pay for reports today, but we commit to a fast response and we will not pursue legal action against good-faith research conducted under these terms.
Last updated 2026-07-17.
Scope
In scope: the skarn binary and its source, the customer portal at account.getskarn.com, the license service API, and getskarn.com. Out of scope: third-party services we depend on (Cloudflare, Paddle, SMTP2GO, AWS) - report those to the vendor directly; social engineering, physical attacks, and denial-of-service testing against our production infrastructure.
How to report
Email [email protected] with a description of the issue, the steps to reproduce it, and its impact. A plain-text report to this address is read by a human within one business day. We do not yet publish a PGP key for encrypted reports; if that changes, it will be linked here and from security.txt. Do not open a public GitHub issue for a security finding - the skarn source repository is private, but the sample scenario still applies to any adjacent public repos.
Include, where relevant: the affected command or endpoint, a proof-of-concept (redacted of any real secret you used to demonstrate it), the skarn version or portal timestamp, and your assessment of severity.
What happens after you report
- Acknowledgment within 1 business day. You will hear from a human, not an autoresponder alone.
- Initial severity assessment within 5 business days. We will tell you whether we can reproduce it and how we are scoping the fix.
- A fix or mitigation timeline communicated to you, prioritized by severity: critical issues (remote code execution, secret exposure, authentication bypass) get the fastest turnaround.
- Credit, if you want it. With your permission, we will name you in the fix's release notes or on this page.
- No bounty today. We do not run a paid program yet. If that changes, this page will say so.
Safe harbor
Security research conducted consistent with this policy is authorized: we will not pursue legal action, and we will not report you to law enforcement, for good-faith testing that (a) stays within the scope above, (b) avoids privacy violations, service disruption, or destruction of data, (c) uses only accounts and data you own or have explicit permission to test, and (d) gives us a reasonable window to fix the issue before any public disclosure. If a third party initiates legal action related to your research and you have complied with this policy, we will state publicly that your research was authorized.
This safe harbor does not cover the third-party services listed under Scope above, which set their own policies.
Coordinated disclosure
We ask for 90 days from our acknowledgment before public disclosure, or until a fix ships, whichever is sooner, and we will tell you as soon as a fix is out so you are not left guessing. If we miss agreed timelines without explanation, disclose on your own schedule - the point of this policy is trust in both directions.