Reporting a security vulnerability — version 1.0
In effect from 2026-09-21. Previous versions remain available at/legal/security/versions/.
Reporting a security vulnerability
If you believe you have found a security vulnerability in Aporta, please tell us. This page says where to send it, what we treat as in scope, and what we commit to once it arrives.
How to report
Email [email protected].
If you want to encrypt your report, our OpenPGP key is published at
https://aportasystems.com/.well-known/pgp-key.txt. Its fingerprint is:
3298 6A25 063A 6D72 A972 A403 36A7 2868 90CE 06EC
Check the fingerprint before you use the key. Encryption is optional; an unencrypted report is just as welcome.
A useful report says what is affected, how to reproduce it, and what you think the impact is. If you have a proof of concept, include it. Tell us how you would like to be contacted.
The same address is listed in https://aportasystems.com/.well-known/security.txt.
What is in scope
- The Aporta browser extension, as published in the Chrome Web Store and Edge Add-ons.
aportasystems.comand its subdomains.- Aporta’s hosted service: the sign-in, vault and audit service the extension talks to, and the administrator dashboards.
What is not in scope
- The AI tools Aporta works with. ChatGPT, Claude, Gemini, Microsoft Copilot and Perplexity are run by their own vendors. A vulnerability in one of them should go to that vendor. If it affects how Aporta protects information on that site, we would like to hear about it too.
- Services Aporta uses. The providers on our sub-processors page run their own disclosure programs, and a vulnerability in their service belongs with them.
- Denial-of-service or load testing, social engineering of anyone at Aporta or a customer, and physical attacks.
Please
- Test only against accounts and data that are yours. Do not access, change or delete another organization’s data.
- If you come across personal information or another customer’s data, stop, do not keep a copy, and tell us in your report.
- Give us a reasonable chance to fix the problem before you disclose it publicly. We will agree a date with you.
What we commit to
- We will acknowledge your report within three business days.
- We will tell you whether we can reproduce it, and keep you informed while we work on it.
We do not promise a time to fix. The right fix depends on what you found, and a date we could not keep would be worse than none.
Aporta is a small team. Reports are read during business hours, and there is no round-the-clock cover.
No bug bounty
We do not run a bug bounty and we do not pay for reports. If you would like to be credited when a fix ships, say so in your report and we will name you.
Safe harbor
If you make a good-faith effort to follow this policy while researching and reporting a vulnerability, we will treat your research as authorized, and:
- We will not take legal action against you, or ask anyone else to, over that research. That includes claims under anti-hacking laws, such as the U.S. Computer Fraud and Abuse Act, and claims under anti-circumvention rules, such as the DMCA, for work that stays within this policy.
- We waive the parts of our terms of service that would otherwise forbid that research, but only as far as needed to do it within this policy.
- If someone else takes legal action against you over research that followed this policy, we will make it known that we authorized it.
This covers only systems Aporta owns and operates, as listed under What is in scope. We cannot authorize testing of anyone else’s systems: not the AI tools Aporta works with, not the services Aporta uses, and not a customer’s own environment. Their own policies govern that testing.
Following this policy means, in particular:
- testing only against your own accounts and data
- stopping and telling us if you come across anyone else’s data
- not degrading the service for other people
- giving us a reasonable chance to fix the problem before you disclose it
If you’re unsure whether something you plan to do is within this policy, ask us at [email protected] before you do it.