Sequoia PGP is a leading provider of secure communication and authentication in the OpenPGP space.
We are committed to protecting the privacy and security of our users with a particular emphasis on the most vulnerable people in our society: activists, journalists, lawyers and their clients.
We are working to achieve this goal by writing specifications, and building libraries and programs for developers, adminstrators, and end users. The specifications that we author, and the software that we author is the sole scope of this bug bounty program.
This bug bounty program is paid for by the Sovereign Tech Resilience Program.
As a complement to the program rules and testing policy:
We are happy to thank everyone who submits valid reports that help us improve the security of Sequoia's specifications and software, however, only those that meet the following eligibility requirements may receive a monetary reward:
We use CVSS to rate and categorize vulnerabilities. Any vulnerability will be publicly disclosed after sufficient time has passed for operating system distributions like Debian to deploy updates, and dependant applications to prepare a new release.
Advisories will be published on our mailing-lists, and external mailing-lists like oss-security. When appropriate we will also create an ecosystem-specific advisory. For instance, in the case of Rust code, we will submit an advisory to the rustsec advisory database.
Please understand that we handle the full disclosure process and expect that you do not disclose any findings yourself, we will include researcher credits, if requested.
The process that we follow is described in this document.
Scope Type | Scope Name |
---|---|
undefined | buffered-reader |
undefined | nettle-sys |
undefined | nettle-rs |
undefined | SHA1-CD |
undefined | sequoia-openpgp |
undefined | sequoia-autocrypt |
undefined | sequoia-ipc |
undefined | sequoia-net |
undefined | Shared OpenPGP Certificate Directory |
undefined | sequoia-cert-store |
undefined | sequoia-wot |
undefined | sequoia-policy-config |
undefined | rpm-sequoia |
undefined | sqv |
undefined | sq |
undefined | sqop |
undefined | octopus |
undefined | sequoia-git |
undefined | OpenPGP Cert Directory Specification |
undefined | Sequoia git Specification |
undefined | chameleon |
web_application | Web of Trust Specification |
Scope Type | Scope Name |
---|---|
web_application | Anything related to https://sequoia-pgp.org |
This program have been found on Yeswehack on 2024-04-10.
FireBounty © 2015-2025