Security

How to report something you have found, and what happens after you do.

Reporting

Email security@bulleted.app. Include enough to reproduce the problem — a URL, the request, what you expected and what happened instead. If it is easier to show than to describe, a short recording is welcome.

If you would rather not use email, anything that reaches the maintainer is better than a report that never gets sent. Please do not open a public issue for a vulnerability before it is fixed.

What happens next

Bulleted is maintained by one person, so the honest answer is that reports are read and acted on as soon as they are seen rather than within a fixed window. You will get a reply acknowledging the report, a note when the cause is understood, and another when a fix is deployed. If a report turns out not to be a problem, you will be told why rather than met with silence.

Credit is offered for anything reported here and fixed, under whatever name you prefer. Say if you would rather not be named.

If it is content rather than a vulnerability

Same address, different page: Abuse and removal covers reporting content on this site and having your own taken out of the index, including what removal can and cannot do. You do not need an account and you do not need to explain yourself.

What is in scope

This service, its OAuth flow, and the records it writes on your behalf. The interesting parts, in roughly the order they matter: anything that lets one account read or write another account's data; anything that leaks or misuses the OAuth tokens the server holds; anything that gets script onto a page in a way the Content Security Policy does not stop; and anything that turns a public read into a write.

A personal data server is somebody else's software. If the problem is in a PDS, in the AT Protocol itself, or in another client, it belongs with them — though if you are unsure which side of the line it falls on, send it here and it will be passed along.

What is not a vulnerability

Your bullets are public. They are records in your own repository, readable by anyone with the address, without this service's cooperation. Privacy says so at greater length. A report that public data can be read is not a finding; it is the design, and the page that explains it is one click from every screen.

Also not findings, unless you can show real impact: missing headers on responses that carry nothing, rate limits you reached by trying to reach them, output from an automated scanner with no working example attached, and reports that a version number appears somewhere.

Testing

Test against your own account. Do not use somebody else's data to demonstrate a problem — a report that reads a stranger's records to prove that it can is a report that did the thing it is warning about. Denial of service and load testing are not welcome; the service runs on one small machine and taking it down teaches nobody anything.

Nobody will be pursued for a good-faith report that follows the paragraph above.

The machine-readable version of this page is at /.well-known/security.txt.