Use a clear subject
Email support@c2.pa with “Security report” and the affected ProvSeal surface in the subject line.
Responsible disclosure
If you believe you have found a security vulnerability in a ProvSeal-owned website or distributed product, please report it privately so it can be investigated before public disclosure.
Do not email private keys, passwords, authentication tokens, confidential certificates or sensitive media. Start with a redacted description and ask for a safer transfer method if evidence contains secrets.
Email support@c2.pa with “Security report” and the affected ProvSeal surface in the subject line.
Share only the information required to reproduce and understand the issue. Redact personal data and third-party secrets.
Please allow time for investigation and remediation before posting details that could place users or systems at risk.
Report contents
A concise, reproducible report is easier to triage than a large unstructured attachment.
ProvSeal should never need a private signing key to reproduce a product issue. Use test material and remove secrets from screenshots, logs and sample files.
Provide the URL, browser-extension version, product version or component where the issue was observed.
Explain the unexpected behavior, required conditions and realistic security impact.
List the smallest reliable sequence, expected result and actual result.
Include limited screenshots, logs or a proof of concept that uses your own accounts, systems and test media.
Provide a reliable way to ask follow-up questions and tell us whether you plan to publish the finding.
Please keep testing proportionate and limited to systems, accounts and data you are authorized to use.
Do not access, modify, retain or disclose another person's data. Stop testing if sensitive information becomes visible.
Do not perform denial-of-service testing, destructive actions, spam, brute force or high-volume automated scanning.
Use your own accounts, files, certificates and non-production examples wherever possible.
Send enough detail to reproduce the issue, then avoid further exploitation beyond what is needed to demonstrate impact.
The report is reviewed for scope, reproducibility and likely impact. Additional information may be requested.
If confirmed, the issue is prioritized and remediation is planned according to severity and affected users.
Where practical, communication continues through remediation and a reasonable disclosure timeline is coordinated with the reporter.
Send a concise, redacted description first. Do not attach private keys, sensitive media or third-party data.