security
Vulnerability Disclosure Policy
ChainStrip · Last updated: 2026-08-30
ChainStrip builds security tooling, so we hold ourselves to the standard we sell. If you believe you've found a security issue in our product or our web properties, we want to hear from you, and this page explains how that works and what you can expect from us.
Scope
In scope:
- The ChainStrip product: the CLI, analysis pipeline, transform engine, and any artifacts we distribute (packages, container images, release binaries)
- Our web properties: chainstrip.com and its subdomains
- Our distribution channel: the integrity of our published releases and update mechanism
Out of scope:
- Customer deployments of ChainStrip. The product is self-hosted; testing an instance running in someone else's environment requires that organization's authorization, which we cannot grant. Product vulnerabilities you discover in the course of authorized work on a customer deployment are absolutely in scope to report to us — the testing authorization just isn't ours to give.
- Denial-of-service and volumetric testing
- Social engineering, phishing, or physical attacks against ChainStrip personnel
- Third-party services we use (registrar, email, hosting provider) — report those to the respective vendor
- Findings without security impact (missing hardening headers on static pages, SPF/DMARC configuration commentary, version disclosure alone)
How to report
Email security@chainstrip.com with:
- A description of the issue and its security impact as you understand it
- Reproduction steps or a proof of concept — for product issues, the ChainStrip version and a minimal input that triggers the behavior
- Your assessment of severity, if you have one
- How you'd like to be credited, if at all
If you prefer encrypted mail, use our PGP key (also listed in security.txt). Fingerprint: 1272 C605 54DD 3143 C11D D0F3 5579 3FD3 FF69 E118.
What we commit to
- Acknowledgment within 3 business days of your report
- An initial assessment within 10 business days, including whether we confirm the issue and our view of severity
- Status updates at reasonable intervals until resolution — you will not be left wondering
- Notification to affected customers and an advisory when a confirmed product vulnerability is fixed
- Credit in our advisory and acknowledgments, if you want it
We do not currently run a paid bug bounty. This is a disclosure program: what we offer is a fast, honest, technically competent response.
Coordinated disclosure
We ask that you give us a reasonable window to remediate before public disclosure — 90 days is the default we work to, and we'll tell you early if a fix needs longer and why. We're glad to coordinate publication timing, and for confirmed issues we'll share our advisory draft with you before it goes out.
Safe harbor
We consider security research conducted in good faith and within this policy to be authorized. We will not initiate legal action against you for good-faith research that: respects the scope above, avoids privacy violations and data destruction, does not degrade service for others, and gives us a reasonable opportunity to remediate before disclosure. If you're ever unsure whether something is covered, ask first at security@chainstrip.com — we'd rather answer a question than handle an incident.
This authorization applies only to systems we own. It cannot extend to our customers' environments or to third-party services.
Questions about this policy: security@chainstrip.com