What this covers
This policy applies to the PineKey service at pine-key.com (website, web vault and API), the operator panel at ops.pine-key.com, and the Chrome/Edge extension and command-line client we publish. It covers security weaknesses: anything that could expose vault data or account information, bypass authentication, access another account, or let an attacker act as PineKey.
Out of scope: our providers’ own systems (Hetzner, Cloudflare, Resend, MXroute), denial-of-service and volume testing, spam or social engineering of our staff or users, physical attacks, and findings that only apply to outdated browsers. Report provider issues to the provider.
How to report
Email [email protected] with the subject “Security report”. Describe the affected page or client, the steps to reproduce, and the impact you see. Use your own test account; ask for one if you do not have one. Before sending screenshots, exports or other evidence that contains secrets, ask us for a suitable channel; we do not publish a PGP key yet.
Write in English or Swedish. We read every report ourselves; there is no triage service in between.
What we promise
- An acknowledgement within 3 business days (Monday to Friday, Swedish public holidays excluded).
- An initial assessment, with a severity and a plan, within 10 business days.
- A fix or mitigation within 90 days of the report for confirmed issues, sooner for anything that exposes vault data or lets someone sign in as another user. If we need longer we say so and why.
- Updates when the assessment changes and when the fix is live, and a note of what changed in our public operations log.
- Credit by name or handle on this page if you want it; silence if you prefer.
We do not pay bounties at this stage. We say that up front so nobody is surprised.
Rules for research
- Only test accounts you created, and only data you put there.
- Stop and report as soon as you see another person’s data; do not read, copy or keep it.
- No denial of service, no mass scanning that disrupts the service, no changes to data you do not own.
- No social engineering, phishing or physical access attempts.
- Keep the finding between you and us until it is fixed, or until 90 days have passed since your report, whichever comes first; coordinate the wording of any publication with us.
Safe harbour
Research done in good faith within these rules is authorised. Bröderna Saxin AB will not pursue legal action or a police report against you for it, and we will not ask you to delete a finding you report. We cannot authorise actions against third parties or waive laws that bind you; if you are unsure whether something is covered, ask first. If a third party starts legal action because of research done under this policy, we will state that your actions were authorised by us.
Reports so far
No external reports have been received yet. Fixes from our own reviews are listed in the operations documentation that ships with each release.