Diffuse security reporting
Coordinated disclosure protects people who may rely on Diffuse in physically dangerous situations.
Report privately
Email diffuse@offlineprotocol.com with “SECURITY” in the subject. Include impact, affected version, and a minimal reproduction. Do not open a public issue for an unpatched vulnerability.
Safe research
Do not access another person’s data, disrupt the production service, test against real users, or retain illegal material. Use local or staging fixtures. Production testing requires written authorization.
Response target
Diffuse aims to acknowledge a report within 72 hours, provide a triage decision within seven days, and coordinate remediation and disclosure based on severity.
Priority areas
Identity or signature forgery, revocation bypass, metadata deanonymization, archive-key compromise, source-capture SSRF, safety-screening bypass, and resource-amplification attacks receive priority.