Security
How to report something, and what we already publish about how this service is built. Nothing on this page is new — every line below points at a document that is already public, and the policy at api.bluefoxedge.ai/security-policy governs.
Report an issue
Email support@bluefoxedge.ai with the subject line "Security report" so it is triaged ahead of general support. Tell us the affected endpoint or page, how to reproduce it, and what you saw. If it involves a signed receipt, include the receipt bytes you checked. Please do not include another person's data in a report.
The machine-readable contact record is published at /.well-known/security.txt (RFC 9116). The full policy is at api.bluefoxedge.ai/security-policy.
What to expect
We acknowledge reports on a best-effort basis and prioritise fixes by severity. We do not run a paid bounty programme. Please give us a reasonable window to remediate before public disclosure, and coordinate the timing with us.
Out of scope
Testing must not degrade the service for anyone else: no denial-of-service, no volumetric testing against production, and no access to data that is not yours.
What we already publish
The signing keys every receipt checks against — /.well-known/jwks.json
The check itself, runnable, with the traps named — including the norm that a checker MUST NOT follow the jwks_url inside a receipt; pin the key set out of band at the published address above — run the check
What the transparency log deliberately does not do — the limits of our own evidence, in our own words — the checkpoint
How claim text is stored and who else sees it — the Privacy Policy's storage and subprocessor sections
This policy, machine-readably — /.well-known/security.txt
We hold no third-party security certification today. When that changes, this page will say so and name it.
← BlueFox