Beta testing of the app is out. Early users are accepted. All terms and conditions apply. Get now ›

Security and responsible disclosure

Security and Responsible Disclosure

This page describes, at a general level, how we protect the data entrusted to us, and how a security researcher can report a vulnerability to us safely and in good faith.

1. Our Security Approach

We deliberately do not publish detailed technical specifics where disclosure would itself weaken security.

2. Reporting a Vulnerability

If you believe you have found a security vulnerability in our website, apps, firmware or cloud services, please tell us before telling anyone else. Email contact@adarna.us with the subject line "Security — vulnerability report" and include:

3. What We Ask of Researchers

4. What You Can Expect From Us

We do not currently operate a paid bug bounty. We will not pursue legal action against a researcher who follows this Policy in good faith.

5. Out of Scope

The following are generally not treated as vulnerabilities: reports generated solely by automated scanners without a demonstrated impact, missing security headers with no exploitable consequence, weaknesses in third-party services we do not control, social engineering, and issues requiring physical access to an unlocked device.

6. If a Breach Occurs

No system is perfectly secure and we will not claim otherwise. If a breach affecting personal data occurred, we would investigate and contain it, notify affected users and the appropriate United States regulators as applicable United States federal and state breach-notification laws require, and publish a plain account of what happened and what to do.

7. Protecting Your Own Account

Use a unique password, keep your credentials private, keep your apps updated, and tell us at contact@adarna.us if you think your account has been accessed by someone else.