If you find a vulnerability in a Vassbrekke AS product or in repositories under github.com/Vassbrekke, email contact@vassbrekke.no with:
- The affected product or repository
- A description of the issue and how to reproduce it
- Impact, if you know it
Please do not open a public GitHub issue for security reports.
We do not currently run a paid bug bounty.
Publishing source (for example the PrivyDeck extension or the PrivBeacon on-prem agent) is so you can inspect it. That is not a third-party security audit and not a promise of a SLA.