Security
Responsible Disclosure
BootIntel is a security product. Every reported issue gets a human reply. This page describes how to report, what's in scope, what to expect, and how we credit researchers.
Where to report
- [email protected], preferred for vulnerability reports.
- /.well-known/security.txt RFC 9116 advertisement; machine-discoverable.
- PGP: on request. Mention "PGP requested" in your first email and we'll exchange keys before any sensitive payload.
In scope
- • bootintel.com, public marketing, auth, dashboard, and API surfaces.
- • The BootIntel mobile app on iOS and Android (boot-log capture, push notification handling, signed‑in flows).
- • Findings in our analysis output that misrepresent severity, provenance, or evidence.
- • Issues that allow one user's data to leak to another (logs, scans, devices, billing).
Out of scope
- • Volumetric DDoS / brute-force / spam, please don't.
- • Reports from automated scanners with no exploitability narrative.
- • Findings on third-party services (Stripe, Resend, Cloudflare, Google OAuth), please report directly to them.
- • Social engineering of BootIntel staff.
- • Self-XSS that requires a user to paste attacker content into their own dev console.
Safe harbor
We will not pursue legal action against good-faith research that stays within scope, avoids degrading service for other users, never accesses other users' data beyond what's necessary to demonstrate the issue, and gives us a reasonable opportunity to fix before public disclosure.
What to expect
- < 3 business days, human acknowledgement of your report.
- < 10 business days, triage outcome (accepted, duplicate, out-of-scope, won't-fix).
- 90 days, default coordinated-disclosure window for accepted reports; we'll request an extension if a fix needs more time and tell you why.
Acknowledgments
Researchers who have responsibly disclosed are listed here with their permission. If you'd like to be added (or removed), include your preferred name and any handle/link in your report.
. No public acknowledgments yet. Be the first.