Found a vulnerability? Here is where it goes

Conchshell holds SSH keys and passwords for other people's servers. A flaw here is not an inconvenience, so a report is worth more to us than the embarrassment costs.

Where to send it

EMAIL
support@conchshell.app. Write in English or Russian. If the finding is sensitive enough that email is the wrong place for it, say so in one line and we will agree on something better.
GITHUB
A private security advisory on the repository, if you would rather have a thread with a record. This is the channel with the fastest route to a fix, because it is where the fix is written.

What to expect

A REPLY WITHIN 3 DAYS
Even if it is only to say it was received and who is looking at it. If three days pass in silence, assume the message was lost and send it again.
AN ASSESSMENT WITHIN 10 DAYS
Whether we agree it is a vulnerability, how severe we think it is, and when we expect to fix it — or why we think it is not one, in enough detail for you to argue back.
A FIX, AND YOUR NAME ON IT
Credit in the release notes and the advisory, under whatever name you choose, unless you ask us not to. There is no money: this is one person's project and pretending otherwise would be worse than saying so.

What counts

IN SCOPE
The application in any released build or on the main branch, this website, the update endpoint, and the vault format itself. A flaw in the format is as real as a flaw in the code that implements it.
OUT OF SCOPE
Findings that need an attacker who already runs code as you — the threat model says so in the open and does not pretend otherwise. Reports from a scanner with nothing behind them. Missing headers on a page that has nothing to protect.
NOT SURE?
Send it. Deciding what is in scope is our job, not a hurdle to clear before you are allowed to help.

What we promise you

If you find something while genuinely trying to make this safer, we will not report you to anyone, will not send a lawyer after you, and will not ask your employer about you. That holds even if you break something on the way, as long as you tell us. It stops holding if you go after other people's data, hold a finding for payment, or publish before we have had a fair chance to fix it — which is not a rule against publishing, only against publishing first.

What not to do

SOMEONE ELSE'S SERVERS
Test against your own machines. The application connects wherever you point it, and a report that involved a host you do not own is one we cannot accept.
FLOODING
Load tests, denial of service and mass automated traffic tell us nothing we want to know and take the site down for people who came to download a client.
PEOPLE
No phishing, no pretexting, no approaching anyone involved in the project as though you were someone else.

Who to write to

Conchshell is not a company. It is one person's project, published under the MIT licence, and support@conchshell.app reaches them. Questions about this website, about what it collects, about the licence, or about anything on these pages — that address is the whole of it.

Last updated: 2026-08-05

Updated 2026-08-04 · v2.11.0