Report a vulnerability.

How to report a security issue in PasswordRadar, what is in scope, and what happens after you write.

Contact
security@passwordradar.eu
Machine-readable
/.well-known/security.txt
Updated

Found something?

Email security@passwordradar.eu. We aim to acknowledge within 3 business days. We won’t pursue legal action against good-faith research that stays within the scope below and gives us reasonable time to fix.

Scope

In scope

  • api.knownpass.com, the API
  • admin.knownpass.com, the admin console (not open yet)
  • passwordradar.eu and this site
  • knownpass.com, the former domain
  • The reference client, once its repository is published
  • The hashing scheme and the threat model itself

Out of scope

  • Volumetric denial of service
  • Third-party services we use (report to them)
  • Social engineering of the operator
  • Automated-scanner output without a working proof of concept
  • Reports that require physical access

What to include

  • Steps to reproduce, or a proof of concept.
  • Which component, and which URL or endpoint.
  • Your assessment of impact.
  • Whether you want to be credited, and how.

Don’t include real end-user data. If you need to demonstrate an issue with the dataset, use your own test passwords.

What to expect

  • We aim to acknowledge within 3 business days.
  • A fix timeline once we’ve reproduced the issue, and a note when the fix ships.
  • Credit on this page if you want it. No bug bounty yet.

PGP

planned The public key and fingerprint will be published here and in security.txt. Until then, email in plain text and ask for an encrypted channel if the report is sensitive; we’ll set one up before you send details.

On our side

  • The API never receives a password or a full hash. What it does receive is described in the threat model.
  • The API’s own log holds key ID, timestamp, response code and latency. Its web server, like this website’s, keeps a standard access log (IP address, time, request line with the prefix, referrer, user agent) for at most 15 days; the privacy policy has the details.
  • API keys are per customer. Rotating them is planned for the admin console, which isn’t open yet; until then, email hello@passwordradar.eu for a new key.
  • EU hosting, operated by KnownPass s.r.o.

Thanks

No reports yet. Names of reporters who want credit will appear here.