CHRONO GATE0 online
Security disclosures
How to report a vulnerability in Chrono Gate.

We take security reports seriously. Our backend, firmware, and hardware are in scope, and we respond to every disclosure. Researchers who act in good faith are welcome.

Scope
In scope
  • chronogate.io web application (server and embedded HTML).
  • Raspberry Pi Zero 2W firmware shipped via our OTA channel.
  • API endpoints under /api/ (authenticated and device-auth).
  • Payment flow (Stripe and Revolut integrations we control).
Out of scope
  • Third-party services (Stripe, Revolut, Hetzner, GitHub) — report to those providers directly.
  • Physical attacks requiring possession of a platform you do not own.
  • Social engineering of our staff or customers.
How to report

Send details by email with a clear title and steps to reproduce. Please include the affected URL or firmware version and, where possible, a minimal proof of concept.

PGP / encrypted email

Encrypted email is available on request. Ask us at security@chronogate.io and we will share a public key and fingerprint through a verifiable channel.

What to expect
  1. Initial acknowledgement within 1 business day.
  2. Triage and severity assessment within 5 business days.
  3. Fix target of 90 days for confirmed vulnerabilities; critical issues go faster.
  4. Coordinated public disclosure once a fix is deployed, with credit to the reporter if requested.
What we ask
  • Do not perform destructive testing, denial-of-service, spam, or actions that degrade service for others.
  • Do not run automated mass scanners against our infrastructure; targeted manual testing only.
  • Do not access, copy, or retain customer data beyond the minimum needed to demonstrate the issue.
  • Wait for us to deploy a fix before any public disclosure; we aim for the 90-day window.
Safe harbor

If you make a good-faith effort to comply with this policy, we will not pursue or support legal action against you for your research activity. Activities outside this policy — especially those that harm users — are not protected.

Recognition

Be the first. We list researchers here — with your consent — after the report is resolved and disclosed.

Machine-readable policy

We publish a signed security.txt at /.well-known/security.txt following RFC 9116 so automated tools can discover these details.