Security Disclosure
1. Reporting a vulnerability
If you find a security problem, report it privately to contact@uillabs.com.
No PGP key is published yet; reports may be sent unencrypted to the address above, and a key
will be published here when available.
Please include:
- what the problem is and where (component, version, file or endpoint);
- how to reproduce it, as concretely as you can;
- what impact you think it has;
- how you would like to be credited, or if you prefer to stay anonymous.
Do not open a public issue for an unreported vulnerability, and do not test against systems or accounts you do not own or have permission to test.
2. No bug bounty
There is no bug bounty program and no payment or reward is promised for reports. Reports are welcome as a contribution to a free research project. Credit can be given if you want it, but no other compensation is offered.
3. Good-faith safe harbour
If you act in good faith — testing only your own systems or accounts, or a copy you run yourself; not accessing, changing, exfiltrating or destroying other people’s data; not degrading the service; and reporting promptly and privately — the author will not pursue legal action over the research itself. This is a statement of intent by the author and does not bind third parties, does not authorise testing of infrastructure the author does not control, and does not override any law.
4. No security guarantee
No security guarantee is given. This is experimental software, developed by one individual with
AI assistance, and it is not warranted to be secure. It may contain vulnerabilities, may not
have been audited, and may change. Do not rely on it to protect anything valuable or sensitive.
See 02-LIMITATION-OF-LIABILITY.md.
5. Scope
In scope: the project’s own software and the hosted services the author operates. Out of scope: third-party software, third-party infrastructure, social engineering, and physical attacks. Third-party vulnerabilities should be reported to their own maintainers.