Security Acknowledgments
Researchers who reported issues to us. The bug-bounty pool is 3% of revenue; payouts flow once revenue exists.
Severity → payout
| Severity | Description | Payout (USD) |
| Critical | Remote code execution, persistent auth bypass, full account takeover | $500 |
| High | Significant data exposure, privilege escalation to Pro without payment | $200 |
| Medium | Cross-origin data leakage, denial-of-service affecting other users | $75 |
| Low | Information disclosure that doesn't compromise other users | $25 |
| Info | A non-exploitable finding that still helps us improve | $10 |
Pool status
— Current pool balance: $0 (no revenue yet; pool activates when revenue exists).
The pool accrues at 3% of revenue until spent. The ledger is /state/bounty-pool/ledger.jsonl on our side; we publish the total here monthly. The critic-agent (configurable daily review at 07:55) generates internal "researcher" findings that go into the same pool accounting for transparency.
Researchers
No external disclosures yet. When the first finding arrives, it will be acknowledged here within 7 days of triage.
How to report
- Email
security@seele.agency (PGP key on request)
- Or open a private issue at GitHub Security Advisories
- Subject line must include "security disclosure" to avoid spam filtering
Disclosure policy
- We aim to acknowledge within 48 hours of receipt.
- We aim to triage within 7 days.
- Coordinated disclosure: please wait until we mark "fixed" or 90 days, whichever comes first.
- No legal action against researchers who follow this policy in good faith.
- Out of scope: denial-of-service via volume, physical attacks, social engineering, automated scanners without target validation.
Scope
- In scope: seele.agency, xkg-desktop, xkg-server, cluster-hub :8090, xkg-mobile-flutter (TestFlight builds), and any subdomain we operate.
- Out of scope: third-party sites (grok.com, claude.ai, chatgpt.com, gemini.google.com) — please report those to the vendor.
- Rewards vary by scope; in-scope items use the table above, out-of-scope referrals still get a "thank you" on this page.
What we won't do
- Threaten legal action against good-faith research.
- Retroactively define your report as "out of scope" after you've already written it up.
- Hide acknowledgment. Every valid report appears here.