Vulnerability Disclosure Policy
Last updated: May 18, 2026
In short: Found a security issue in Dikt? Email security@dikt.app. We welcome good-faith research, won’t pursue legal action against researchers who follow this policy, and will publicly credit you if you’d like. We do not currently offer a paid bounty.
Reporting a Vulnerability
Send a report to security@dikt.app. To help us triage quickly, please include:
- A clear description of the issue and its potential impact.
- Step-by-step instructions to reproduce it.
- The affected component — a URL on dikt.app, or the Dikt for Windows app version (Settings → About).
- Any proof-of-concept code, screenshots, or logs.
We do not currently publish a PGP key. Please avoid including third-party personal data or live credentials in your report.
Our Commitment
- We aim to acknowledge your report within 5 business days.
- We’ll keep you informed as we investigate and work toward a fix.
- Once resolved, we’ll publicly credit you by name or handle if you wish — just let us know.
Safe Harbor
If you make a good-faith effort to comply with this policy during your research, we will consider your testing authorized. We will not pursue or support legal action against you, and will not refer you to law enforcement, for accidental, good-faith violations.
This safe harbor does not apply to actions taken in bad faith, such as data exfiltration, extortion, or intentional harm to users.
Scope
In scope
- The dikt.app website and its official APIs.
- The Dikt for Windows desktop application.
Out of scope
- Third-party services we rely on (e.g. Stripe, Supabase, OpenAI, Anthropic) — report those to the respective vendor.
- Volumetric or denial-of-service attacks, and automated scanner output without a demonstrated, exploitable impact.
- Social engineering, phishing, or physical attacks against Jyvin Company, its staff, or users.
- Best-practice or configuration suggestions with no concrete security impact (e.g. missing headers without an exploit).
Guidelines
- Only test against your own accounts and data. Never access, modify, or delete data belonging to other users.
- If you encounter another user’s data, stop immediately and report it — do not download or retain it.
- Do not run attacks that degrade service for others (DoS, brute force at volume, spam).
- Give us a reasonable opportunity to remediate before any public disclosure — we ask for up to 90 days, and will work with you on timing.
Rewards
Dikt does not currently operate a paid bug bounty program. We genuinely value the security community and offer public acknowledgment for valid, previously unreported vulnerabilities.
Contact
Security reports: security@dikt.app
This policy is also published in machine-readable form at /.well-known/security.txt per RFC 9116.