Security and safety reporting
Kensora handles sensitive mental-health information, and it ships safety features that show support resources when someone's words are the kind a person in danger might use. A weakness in either one matters here, and both get the same private front door.
What to report privately, never in public
Some findings are unsafe to describe in public, now or once the repository and its issue tracker open, either because they expose people before a fix exists or because the reproduction itself contains wording that should not sit in an open space. Please send both kinds below through the private route.
Security vulnerabilities
Anything that could expose user information, weaken encryption, or compromise someone's device or account. The familiar territory of a security report.
Safety weaknesses
Cases where wording a person in danger might use does not cause Kensora to show support resources. An evasion of the layer of behavior that is meant to show support resources once that kind of wording appears. A wrong or dead helpline number anywhere in the app.
These reports are as valuable to this project as any CVE, and they often cannot be written safely in public, because reproducing them means writing out the very wording that does not belong in an open space. The private route exists so you can still tell us.
How to report
Email security@kensora.io. This is the published security contact for Kensora, and it works today. When the public repository opens, GitHub private vulnerability reporting will be added alongside it, and both routes will reach the same people.
In your report, please include:
- What you found.
- How to reproduce it.
- What you believe the impact is.
For safety reports
A content warning at the top of your message is appreciated. Include the language and the exact phrasing that produced the behavior, since precision is what makes the report fixable. Please never include a real person's information or anyone's personal crisis history.
What to expect
Honesty over promises. This is a small project, and reports are read by people rather than a triage system, so this page does not pledge a response window it might not keep. Here is what it does pledge:
- Reports are prioritized by risk to life first. A wrong helpline number outranks almost everything else.
- The aim is to tell you what happened to your report: a fix, a planned fix, or a decision not to change anything, and why.
- Coordinated disclosure is welcome. If you plan to publish your finding, please allow a reasonable window for a fix first.
- Credit is offered for reports that lead to a fix, and pseudonyms are honored. Tell us the name you want used, or tell us none.
Scope
- In scope: the official App Store app, future official apps as they ship, and, once the repository is public, the published code.
- Out of scope: denial-of-service against hosted services, spam, and social engineering of the people who run the project.
If you are not sure whether something fits, send it anyway. The worst case is that it is out of scope.