Responsible disclosure

Security disclosure

If you believe you have found a security vulnerability in a ProvSeal-owned website or distributed product, please report it privately so it can be investigated before public disclosure.

Private reportingGood-faith researchCoordinated disclosure

Protect sensitive material

Do not email private keys, passwords, authentication tokens, confidential certificates or sensitive media. Start with a redacted description and ask for a safer transfer method if evidence contains secrets.

Use a clear subject

Email support@c2.pa with “Security report” and the affected ProvSeal surface in the subject line.

Minimize evidence

Share only the information required to reproduce and understand the issue. Redact personal data and third-party secrets.

Keep it private

Please allow time for investigation and remediation before posting details that could place users or systems at risk.

Report contents

What to include in a useful report

A concise, reproducible report is easier to triage than a large unstructured attachment.

Do not send signing secrets

ProvSeal should never need a private signing key to reproduce a product issue. Use test material and remove secrets from screenshots, logs and sample files.

01

Identify the affected surface

Provide the URL, browser-extension version, product version or component where the issue was observed.

02

Describe the vulnerability

Explain the unexpected behavior, required conditions and realistic security impact.

03

Provide reproduction steps

List the smallest reliable sequence, expected result and actual result.

04

Add sanitized evidence

Include limited screenshots, logs or a proof of concept that uses your own accounts, systems and test media.

05

Share contact details

Provide a reliable way to ask follow-up questions and tell us whether you plan to publish the finding.

Good-faith research guidelines

Please keep testing proportionate and limited to systems, accounts and data you are authorized to use.

Avoid user harm

Do not access, modify, retain or disclose another person's data. Stop testing if sensitive information becomes visible.

Avoid disruption

Do not perform denial-of-service testing, destructive actions, spam, brute force or high-volume automated scanning.

Use test material

Use your own accounts, files, certificates and non-production examples wherever possible.

Report promptly

Send enough detail to reproduce the issue, then avoid further exploitation beyond what is needed to demonstrate impact.

Appropriate reports

  • Security vulnerabilities in c2.pa or ProvSeal-owned web surfaces.
  • Security defects in officially distributed ProvSeal software.
  • Unexpected exposure of sensitive data caused by ProvSeal code.
  • Reproducible failures in permission or trust-boundary enforcement.

Usually outside this process

  • Issues in the C2PA specification or unrelated third-party products.
  • Social engineering, physical attacks or spam campaigns.
  • Automated reports without a reproducible security impact.
  • Product suggestions, support questions or content disputes.

What happens after you report

Triage

The report is reviewed for scope, reproducibility and likely impact. Additional information may be requested.

Investigation

If confirmed, the issue is prioritized and remediation is planned according to severity and affected users.

Coordination

Where practical, communication continues through remediation and a reasonable disclosure timeline is coordinated with the reporter.

Report a ProvSeal security issue privately.

Send a concise, redacted description first. Do not attach private keys, sensitive media or third-party data.