diff --git a/SECURITY.md b/SECURITY.md new file mode 100644 index 0000000..2ba3dde --- /dev/null +++ b/SECURITY.md @@ -0,0 +1,32 @@ +# Security Policy + +## Supported Versions + +We fix security issues as soon as they are found, and release firmware updates. +Each such release is accompanied by release notes, see . + +The latest version can be determined using the file . + +To update your key: +- either visit , or +- use our commandline tool : +``` +solo key update [--secure|--hacker] +``` + +## Reporting a Vulnerability + +To report vulnerabilities you have found: + +- preferably contact [@conor1](https://keybase.io/conor1), [@0x0ece](https://keybase.io/0x0ece) or [@nickray](https://keybase.io/nickray) via Keybase, or +- send us e-mail using OpenPGP to [security@solokeys.com](mailto:security@solokeys.com). + + + +We do not currently run a paid bug bounty program, but are happy to provide you with a bunch of Solo keys in recognition of your findings. + +## Mailing List + +Join our release notification mailing list to be informed about each release: + +https://sendy.solokeys.com/subscription?f=9MLIqMDmox1Ucz89C892Kq09IqYMM7OB8UrBrkvtTkDI763QF3L5PMYlRhlVNo2AI892mO