Vulnerability Disclosure Policy

Conduck

Last Updated: 2026-07-13

Publisher: GigaDuck OÜ (“we,” “us,” “our”) Tornimäe tn 5, 10145 Tallinn, Estonia Registry code: 17501858 (Estonian Business Register) Security contact: [email protected]


Overview

Conduck is built around a simple promise: your conversations, keys, and audio never pass through our servers — because we run none. That design removes whole classes of risk, but no software is flawless. If you have found a security vulnerability in Conduck, the conduck.com website, or the tooling we publish, we want to hear from you — and this page tells you how, and what you can expect from us in return.

We welcome reports from security researchers, users, and anyone else acting in good faith.


Scope

In scope:

Out of scope (not operated by us — please report to the respective project or vendor):

To be clear: a flaw in how Conduck integrates with any of those services, in our release or signing infrastructure, or in the app binaries and tooling we distribute is very much in scope — when in doubt, send it to us and we’ll route it.

Out-of-scope activity — the following are not covered by this policy and must not be part of your research:


How to Report

Email [email protected]. A helpful report includes:

A machine-readable summary of this policy is published at /.well-known/security.txt.

We currently don’t publish a PGP key. If your report contains details you’re not comfortable sending in plain email, say so in a first email without the sensitive parts, and we’ll arrange a secure channel.

Prefer to stay anonymous? You may report the vulnerability indirectly through CERT-EE, Estonia’s national computer security incident response team ([email protected]), and ask them to pass it to us without your identity.


What You Can Expect From Us


How we handle your data: your report reaches GigaDuck OÜ by email and is used solely to triage, fix, and document the issue — including, where the law requires it, evidencing our handling to authorities. We keep the correspondence only as long as needed for that, then delete it. This is ordinary email between you and us; the Conduck app itself still collects nothing. Privacy questions or GDPR requests: [email protected].


Coordinated Disclosure

We ask that you give us the chance to fix the issue before disclosing it publicly: please hold public disclosure until a fix has shipped or 90 days have passed since your report, whichever comes first. If we need longer for a well-founded reason, we’ll explain and agree on a new date with you rather than leave you waiting.


Safe Harbor

We consider security research conducted in good faith and in line with this policy to be authorized. Specifically, if you make a genuine effort to stay within the scope and rules above:

This safe harbor covers our own claims only. It cannot bind third parties, law enforcement, or public prosecutors, who retain their own discretion under applicable law. When in doubt about whether something is covered, ask us first at [email protected].


Recognition

Conduck does not currently offer monetary bug bounties. With your permission, we’re glad to credit you publicly once the issue is fixed, as thanks for a responsibly disclosed report.


Contact

Security reports: [email protected] Everything else: [email protected] GigaDuck OÜ, Tornimäe tn 5, 10145 Tallinn, Estonia · Registry code 17501858