Trust

Vulnerability disclosure policy

If you have found a security issue in Tessera, we want to hear about it, and we will treat you well for telling us. This page sets out what is in scope, what protection you have, and what you can expect from us and when.

Report a vulnerability

security@PLACEHOLDER_DOMAIN.example
Acknowledgement
5 business days
Disclosure window
90 days, coordinated
PGP key
security.txt

Safe harbour

If you make a good-faith effort to comply with this policy during your research, we will consider your activity authorised. We will not initiate or support legal action against you, and if a third party brings action against you for research conducted within this policy, we will make it known that your activity was authorised.

This applies to research, not to consequences. Accessing another customer's data beyond what is needed to demonstrate a flaw, extortion, or public disclosure ahead of an agreed date all fall outside it.

Ask first, if in doubt

If you are unsure whether a particular test is permitted, email us before you run it. We would much rather answer a question than have to decide after the fact.

Scope

In scope

  • The Tessera API and all documented endpoints
  • The public website and its supporting infrastructure
  • The request signing scheme, credential provisioning, and authorisation logic
  • Tenant isolation — any path by which one credential can reach another account's data
  • The erasure coding, placement, and repair logic where a flaw could cause data loss or exposure
  • Client libraries and reference clients we publish

Out of scope

  • Findings from automated scanners submitted without a demonstrated impact
  • Volumetric denial of service, or any test that degrades service for other customers
  • Social engineering of our staff, customers, or storage providers; physical attacks
  • Missing security headers or cookie flags with no exploitable consequence
  • Vulnerabilities in third-party storage providers, which we do not operate — report those to us and we will remove the provider from the pool
  • Reports that require a compromised end-user device, a rooted client, or a malicious browser extension
  • Rate limiting on unauthenticated informational endpoints, absent a demonstrated amplification

Rules of engagement

  • Use only accounts you control, and data you own, for testing.
  • Stop at proof of concept. Do not access, modify, or retain data belonging to anyone else — if you encounter third-party data, stop and tell us.
  • Do not exfiltrate data, establish persistence, pivot to other systems, or degrade the service.
  • Keep testing at a volume that would not be noticeable as load.
  • Give us reasonable time to remediate before disclosing publicly.

Credentials for testing are free to provision through the API, so there is no need to test against anyone else's account. If you need a higher rate limit or a larger quota to demonstrate something, ask and we will arrange it.

What to include in a report

  • A description of the issue and the security impact you believe it has.
  • Reproduction steps precise enough for us to follow without guessing.
  • Affected endpoints, parameters, or components, and the account or credential identifier you used.
  • Any proof-of-concept code, requests, or screenshots.
  • Whether you intend to publish, and on what timeline.
  • How you would like to be credited, if at all.

Reports in English are easiest for us to process quickly. Encrypt with our PGP key if the contents are sensitive.

What happens next

AcknowledgementWithin 5 business days
We confirm receipt and assign a reference. A human reads every report; there is no triage bot standing between you and us.
Triage & validationWithin 10 business days
We reproduce the issue, assign a severity, and tell you our assessment — including if we disagree with your severity and why.
RemediationSeverity-dependent
Critical issues are addressed immediately, with mitigation ahead of a full fix where necessary. We keep you updated as work progresses rather than going silent.
Coordinated disclosure90 days
We aim to resolve and disclose within 90 days of the report. If we need longer, we will explain why and agree a revised date with you rather than let the deadline lapse in silence.
CreditIf you want it
We are happy to credit you publicly by name or handle, or to keep your involvement private. Your choice, stated at any point before disclosure.

Rewards

We do not operate a paid bug bounty programme yet, and we would rather say that plainly than imply one exists. What we do offer today is public credit, a written explanation of how your report was resolved, and service credit or a token of thanks at our discretion for findings with real impact. When a bounty programme launches, it will be announced on this page.

Acknowledgements

Researchers who have reported valid issues and chosen to be credited will be listed here. The list is currently empty, which is the only honest thing a new service can say on the subject.

Send a reportSecurity & compliance