Security
Report a vulnerability.
Found something? Email security@knownpass.com. We aim to acknowledge within 3 business days. We won’t pursue legal action against good-faith research that stays within the scope below and gives us reasonable time to fix.
Scope
In scope
api.knownpass.comadmin.knownpass.comknownpass.comand this site- The reference client
- The hashing scheme and threat model itself
Out of scope
- Volumetric denial of service
- Third-party services we use (report to them)
- Social engineering of the operator
- Automated-scanner output without a working proof of concept
- Reports that require physical access
What to include
- Steps to reproduce, or a proof of concept.
- Which component and which URL or endpoint.
- Your assessment of impact.
- Whether you want to be credited, and how.
Don’t include real end-user data. If you need to demonstrate an issue with the dataset, use your own test passwords.
What to expect
- Acknowledgement within 3 business days.
- A fix timeline once we’ve reproduced the issue, and a note when it ships.
- Credit on this page if you want it. No bug bounty yet.
PGP
planned The public key and fingerprint will be published here and in security.txt. Until then, email in plain text and ask for an encrypted channel if the report is sensitive; we’ll set one up before you send details.
On our side
- The API never receives a password or a full hash. What it does receive is described in the threat model.
- Logging is limited to key ID, timestamp, response code and latency. Logs rotate.
- API keys are per customer and can be rotated in the console.
- EU hosting, operated by KnownPass s.r.o.
Thanks
No reports yet. Names of reporters who want credit will appear here.