maneuler / vault

DRAFT · NOT AN ACTIVE PAID PROGRAM

A proposed scope for security research.

Rewards, legal terms and an operational response team have not been established. No payment or contractual safe harbor is promised. This draft does not authorize testing other users or third-party infrastructure.

Proposed eligible surfaces

Use a controlled environment

Test local builds and devices you own, using synthetic credentials and vault files. Report cross-boundary plaintext disclosure, unauthorized decryption, origin bypass, code execution, file corruption or approval/pinning bypass with a minimal reproduction.

Outside this proposed scope

Unrelated Maneuler apps; Google/Firebase, Apple, Microsoft and other provider infrastructure; social engineering; physical attacks; destructive production testing; denial-of-service; other people's accounts or vaults. Dependency findings need a reproducible impact on Vault. A compromised OS reading its own unlocked process is a documented trust boundary, not an encryption bypass.

Before a paid program can launch

  1. Confirm a dedicated monitored inbox and an owner-held public reporting key.
  2. Approve legal terms, safe-harbor language, eligibility, reward amounts and duplicate-report rules.
  3. Assign triage owners, response targets and a funded remediation process.
  4. Publish the exact eligible versions and a synthetic test environment.

For responsible disclosure today, use the current reporting process. Do not include real secrets.