Diffuse security reporting

Effective 2026-07-31 · Offline Protocol, Inc. · legal@offlineprotocol.com

Coordinated disclosure protects people who may rely on Diffuse in physically dangerous situations.

Report privately

Email diffuse@offlineprotocol.com with “SECURITY” in the subject. Include impact, affected version, and a minimal reproduction. Do not open a public issue for an unpatched vulnerability.

Safe research

Do not access another person’s data, disrupt the production service, test against real users, or retain illegal material. Use local or staging fixtures. Production testing requires written authorization.

Response target

Diffuse aims to acknowledge a report within 72 hours, provide a triage decision within seven days, and coordinate remediation and disclosure based on severity.

Priority areas

Identity or signature forgery, revocation bypass, metadata deanonymization, archive-key compromise, source-capture SSRF, safety-screening bypass, and resource-amplification attacks receive priority.