Found a vulnerability? Here is where it goes
Conchshell holds SSH keys and passwords for other people's servers. A flaw here is not an inconvenience, so a report is worth more to us than the embarrassment costs.
Where to send it
What to expect
What counts
What we promise you
If you find something while genuinely trying to make this safer, we will not report you to anyone, will not send a lawyer after you, and will not ask your employer about you. That holds even if you break something on the way, as long as you tell us. It stops holding if you go after other people's data, hold a finding for payment, or publish before we have had a fair chance to fix it — which is not a rule against publishing, only against publishing first.
What not to do
Who to write to
Conchshell is not a company. It is one person's project, published under the MIT licence, and support@conchshell.app reaches them. Questions about this website, about what it collects, about the licence, or about anything on these pages — that address is the whole of it.
Last updated: 2026-08-05