Vulnerability Disclosure Policy
Published: 20 July 2026 · Machine-readable version: /.well-known/security.txt
We build verification and accountability tools, so we take reports about our own security seriously.
If you believe you have found a vulnerability in an Aramantos Digital product or service, we want to hear from you.
How to report
Email security@aramantos.dev (or support@aramantos.dev, both reach us) with what you found, where, and how to reproduce it.
If it is sensitive, ask for a secure channel in your first mail and we will arrange one.
What we promise
- We will acknowledge your report within 3 working days.
- We will tell you what we conclude and what we changed, honestly, even when the answer is "not a vulnerability".
- If you want one, we will anchor a timestamped record of your report on the Bitcoin blockchain via our own ProveChain service, free, a disclosure receipt proving exactly what you reported and when. That way neither of us can rewrite the history of the disclosure.
- We will credit you if you wish, or keep you anonymous if you prefer.
Safe harbour
If you make a good-faith effort to avoid privacy violations, data destruction and service disruption while researching, and you give us reasonable time to remediate before public disclosure, we will not pursue legal action over your research.
Do not access other people's data, and do not run denial-of-service tests.
Scope
Any service under aramantos.dev and our product domains, plus our published packages.
What we do not offer
We are a small company and do not currently run a paid bug bounty.
What we offer instead is fast, honest handling and a verifiable public record of your disclosure if you want one.