Icecompany builds infrastructure for the private internet. We take vulnerability reports seriously.
Email security@icecompany.tech. Do not open a public GitHub issue for security reports.
Include:
- the affected product (Iceslab, Iceshard, Icepath, Icecore, Iceproxy)
- the version or commit hash
- a clear description of the issue
- reproduction steps or a proof of concept
- the impact you observed
We are a small team. We aim to:
- Acknowledge your report within a few days.
- Give an initial assessment once we have reproduced or understood the issue.
- Keep you updated until it is resolved or closed.
We do not currently run a paid bug bounty program. Reporters are credited in release notes by default. If you prefer to stay anonymous, tell us.
In scope:
- code in repositories under github.com/icecompany-tech
- production services on icecompany.tech and its subdomains
Out of scope:
- third-party services we depend on (report to them directly)
- denial-of-service tests against production infrastructure
- social engineering of staff or users
- physical attacks
A PGP key is available on request. Email security@icecompany.tech and we will send it.