Vulnerability Disclosure Policy
Conduck
Last Updated: 2026-07-13
Publisher: GigaDuck OÜ (“we,” “us,” “our”) Tornimäe tn 5, 10145 Tallinn, Estonia Registry code: 17501858 (Estonian Business Register) Security contact: [email protected]
Overview
Conduck is built around a simple promise: your conversations, keys, and audio never pass through our servers — because we run none. That design removes whole classes of risk, but no software is flawless. If you have found a security vulnerability in Conduck, the conduck.com website, or the tooling we publish, we want to hear from you — and this page tells you how, and what you can expect from us in return.
We welcome reports from security researchers, users, and anyone else acting in good faith.
Scope
In scope:
- The Conduck apps — iPhone, iPad, Mac, Apple Watch, and CarPlay (App Store builds); the Android app joins this scope when it ships
- The conduck.com website
- conduck-connect and any other setup tooling we publish for Conduck
Out of scope (not operated by us — please report to the respective project or vendor):
- Your own AI gateway or server (OpenClaw, Hermes, a custom endpoint) and any machine you run it on
- Hosted AI services and model providers you connect through (such as OpenRouter) and speech providers you bring your own key for
- Apple and Google platform infrastructure (App Store, iCloud, Google Play)
To be clear: a flaw in how Conduck integrates with any of those services, in our release or signing infrastructure, or in the app binaries and tooling we distribute is very much in scope — when in doubt, send it to us and we’ll route it.
Out-of-scope activity — the following are not covered by this policy and must not be part of your research:
- Denial-of-service testing or any activity that degrades a service for others
- Social engineering or phishing of us or of Conduck users
- Physical attacks on people, property, or data centers
- Accessing, modifying, or exfiltrating data that belongs to another person — if proving the issue requires touching someone else’s data, stop at the minimum proof and report
- Spam, or automated scanning at disruptive volume
How to Report
Email [email protected]. A helpful report includes:
- A description of the issue and where it lives (which app, which platform, which version — or which page of the website)
- Steps to reproduce it — a proof of concept, screenshots, or a screen recording all work
- Your assessment of the impact
- How you’d like to be credited, if at all
A machine-readable summary of this policy is published at /.well-known/security.txt.
We currently don’t publish a PGP key. If your report contains details you’re not comfortable sending in plain email, say so in a first email without the sensitive parts, and we’ll arrange a secure channel.
Prefer to stay anonymous? You may report the vulnerability indirectly through CERT-EE, Estonia’s national computer security incident response team ([email protected]), and ask them to pass it to us without your identity.
What You Can Expect From Us
- Acknowledgment within 3 business days of your report.
- An initial assessment within 10 business days, and updates as we work on a fix.
- We treat your report confidentially. We don’t share your details without your permission, except where disclosure is required by law or by security authorities (such as national CSIRTs under EU incident-reporting rules) — and even then we keep your identity out of it wherever possible.
- We address confirmed vulnerabilities without delay. For critical issues, 90 days is our outer bound, not our plan — most fixes ship much faster. App Store review can add a little time to shipping a fix; if resolution takes longer than expected, we will tell you why and keep you in the loop.
- Once a fix is available, we publish an advisory describing the vulnerability, the affected versions, its impact and severity, and what users should do.
- With your permission, we publicly credit you for the discovery.
How we handle your data: your report reaches GigaDuck OÜ by email and is used solely to triage, fix, and document the issue — including, where the law requires it, evidencing our handling to authorities. We keep the correspondence only as long as needed for that, then delete it. This is ordinary email between you and us; the Conduck app itself still collects nothing. Privacy questions or GDPR requests: [email protected].
Coordinated Disclosure
We ask that you give us the chance to fix the issue before disclosing it publicly: please hold public disclosure until a fix has shipped or 90 days have passed since your report, whichever comes first. If we need longer for a well-founded reason, we’ll explain and agree on a new date with you rather than leave you waiting.
Safe Harbor
We consider security research conducted in good faith and in line with this policy to be authorized. Specifically, if you make a genuine effort to stay within the scope and rules above:
- GigaDuck OÜ will not initiate legal action or law-enforcement complaints against you for your research or your report.
- If a third party takes legal action against you in connection with research conducted under this policy, we will make it known that your actions were authorized by us.
- Accidental, good-faith violations of this policy will be treated as just that — talk to us.
This safe harbor covers our own claims only. It cannot bind third parties, law enforcement, or public prosecutors, who retain their own discretion under applicable law. When in doubt about whether something is covered, ask us first at [email protected].
Recognition
Conduck does not currently offer monetary bug bounties. With your permission, we’re glad to credit you publicly once the issue is fixed, as thanks for a responsibly disclosed report.
Contact
Security reports: [email protected] Everything else: [email protected] GigaDuck OÜ, Tornimäe tn 5, 10145 Tallinn, Estonia · Registry code 17501858