Security research

Security Policy

Report vulnerabilities privately, understand what testing is in scope, and read the authorization before you begin.

Report a vulnerability We acknowledge reports within 3 business days.
Email security@tokenburner.net

Reporting a vulnerability

Do not open a public GitHub issue for a security vulnerability.

Email: security@tokenburner.net

Include: clear description, reproduction steps, affected versions if known, your name (or pseudonym) and disclosure preferences. We acknowledge within 3 business days.

Disclosure process

  1. We confirm privately and assess severity.
  2. We develop and test a fix.
  3. We coordinate a disclosure date with the reporter.
  4. We release a patched version with a security advisory.
  5. We credit the reporter (unless they prefer anonymity).

Targets: critical (RCE, sandbox escape, credential exfiltration) within 7 days; high within 30 days; lower in regular releases.

Bug bounty: Not currently. We do not offer payment for reports.

What you may test

In scope: tokenburner.net and its subdomains; our checkout, licence-delivery and update endpoints; and the Tokenburner application running on a machine you own or control.

  • PTY input/output leaking to unintended processes.
  • Screenshot bytes accessible outside the app's data directory without consent.
  • Bypasses of the Tauri capability allowlist.
  • Tampering with auto-update.
  • Code injection via crafted PTY input/output.
  • Privilege escalation through the spawn mechanism.
  • MCP server bypasses — unauthorized cross-pane access, secret leakage, loopback bypass.

Out of scope: any account or data that is not yours; denial-of-service and volumetric load testing; and physical or social-engineering attacks against us, our suppliers, or our people.

  • Vulnerabilities in third-party CLIs run inside Tokenburner panes.
  • Operating system vulnerabilities.
  • Social engineering of users.

A note on our providers: our site, checkout, storage and release hosting run on Stripe, Cloudflare, Resend and GitHub, so testing us necessarily touches infrastructure they operate. What is out of scope is testing their platforms as such — go to their own programmes for that. Testing our configuration of them, at our endpoints, is in scope.

Good-faith research is authorized

If you stay in scope and meet the conditions below, your access is authorised by us, we will not bring or support a legal claim against you for it, we will not treat it as a breach of any agreement between us, and if a third party brings a claim we will state on the record that you were authorised.

Conditions: act in good faith; use the minimum access needed to demonstrate the issue; do not access, modify, retain, or exfiltrate anyone else's data, and stop and tell us immediately if you encounter any; do not degrade the service for others; and report promptly to security@tokenburner.net.

Disclosure timing is your decision

About disclosure timing — a request, not a condition.

We would be grateful for 90 days before you publish, and we will work with you to fix things faster than that. But it is not a condition of this authorisation and it is not a condition of your licence. If you publish sooner, you do not lose the authorisation above, and we will not treat your publication as a breach of any agreement between us, as a ground for suspending or terminating your licence, or as triggering any indemnity you owe us.

Nothing in this Policy restricts your right to publish an assessment of Tokenburner's security. A coordinated-disclosure window that is enforced by withdrawing your protection is a restriction on a performance assessment dressed as a courtesy, and we are not going to write one. This authorisation is ours alone to give and covers only claims we could bring.