Lustig Fairchild
Security

Reporting a security problem

If you have found a vulnerability in one of our apps or on this site, this page is how to tell us, and what we commit to in return. Reports are welcome and answered by a person, and a problem reported early is a problem fixed quickly — a small surface is a real advantage here, and we would much rather hear it from you first.

How to report

Write to security at lustigfairchild dot com. Please include what you found, how to reproduce it, and the app and version, or the page.

This mailbox is for vulnerability reports. Anything else is answered faster at the support address.

What we commit to

  • Reports are read by a person and answered.
  • You are told the assessment, and whether it is going to be fixed.
  • Where a fix ships, an advisory is published, crediting you if you want it.
  • Good-faith research that respects the scope below will not be pursued.

Scope

This domain, and the current release of any app listed on this site. Out of scope: anything needing physical access to an unlocked device, denial of service, automated-scanner output with no working proof of concept, and reports about Apple’s own services.

Advisories

Fixed vulnerabilities are published at /security/advisories/. There are none to date, and that page says so rather than not existing.

There is no bug bounty. This is a disclosure route, not a paid programme, and saying so plainly is more useful than leaving it ambiguous.