Security

Report a vulnerability.

Updated 4 September 2026 · machine-readable version at /.well-known/security.txt

Found something? Email security@knownpass.com. We aim to acknowledge within 3 business days. We won’t pursue legal action against good-faith research that stays within the scope below and gives us reasonable time to fix.

Scope

In scope

  • api.knownpass.com
  • admin.knownpass.com
  • knownpass.com and this site
  • The reference client
  • The hashing scheme and threat model itself

Out of scope

  • Volumetric denial of service
  • Third-party services we use (report to them)
  • Social engineering of the operator
  • Automated-scanner output without a working proof of concept
  • Reports that require physical access

What to include

Don’t include real end-user data. If you need to demonstrate an issue with the dataset, use your own test passwords.

What to expect

PGP

planned  The public key and fingerprint will be published here and in security.txt. Until then, email in plain text and ask for an encrypted channel if the report is sensitive; we’ll set one up before you send details.

On our side

Thanks

No reports yet. Names of reporters who want credit will appear here.