Trust
Security and vulnerability disclosure
What Aldus is built not to hold, and how to tell us about a weakness.
- Last updated
- Operated by
- Kelyan, LLC
- Contact
- security@askaldus.com
In short
- Report a vulnerability to security@askaldus.com.
- We acknowledge a report within 3 business days.
- We will not pursue legal action over research done in good faith under the rules on this page.
- Aldus holds no store passwords, cookies or sessions.
On this page
What Aldus does not hold
The simplest protection is not to have the thing at all.
- Store passwords
- Never asked for, so never held.
- Store cookies and sessions
- Never asked for. Aldus never signs in to a store account.
- Report files
- Read on your device. The files are not stored on Aldus’s servers.
- Account passwords
- None exist. You sign in with a code sent by email.
- Other customers’ data
- Never shared across customers, and never combined for benchmarks.
Report a vulnerability
Write to security@askaldus.com. Please include:
- What you found and why it matters.
- The address or screen affected.
- Steps that let us reproduce it.
- How to reach you.
Leave out other people’s data. If you came across any, tell us where, and delete your copy.
What to expect from us
- Acknowledgement
- Within 3 business days of your report.
- After that
- We tell you what we found, what we will do about it, and when it is fixed.
- Payment
- Aldus does not offer a paid bounty at this time.
In scope
- The website and the web app at askaldus.com.
- Sign-in, workspaces and the separation of one customer’s data from another’s.
- Importing, exporting and deleting data.
Out of scope
- Systems run by our service providers. Report those to the provider; tell us too if Aldus is affected.
- Denial of service, and anything that degrades Aldus for others.
- Social engineering of people, and physical access.
- Spam, and reports from automated scanners with no shown effect.
- Findings that need a device or account already taken over.
Research in good faith
If you follow the rules below, Kelyan, LLC will treat your research as authorized and will not pursue or support legal action against you for it.
- Test only with your own account and your own data.
- If you reach someone else’s data, stop, and report it.
- Do not harm the service or the people who use it.
- Give us reasonable time to fix a problem before you publish it.
- Keep to the law in everything else.
This commitment covers Aldus’s own systems. We cannot authorize testing of anyone else’s.
For machines
- security.txt
- /.well-known/security.txt
- Languages
- English