Security
Thank you for taking the time to look at Kelmscott's security. If you have found something, we want to hear about it.
How to report
Email security@kelmscott.app. Please include:
- A description of the issue
- Steps to reproduce
- The Kelmscott version (Help → About) and your macOS version
- A short impact assessment if you have one: what could an attacker do?
- Whether you have coordinated disclosure with anyone else
Please email first, before any public discussion, so we can triage privately.
What we commit to
- Acknowledgement within 72 hours of your report reaching the inbox.
- Triage within 7 days: a severity assessment and a planned response timeline.
- Fix timelines by severity: critical issues (remote code execution, unauthenticated data access) get an emergency patch within 14 days; high-severity issues ship in the next planned release, within 30 days; medium and low ride the next planned release.
- Coordinated disclosure: we work with you on public-disclosure timing. Standard practice is 90 days from the report or the release of the fix, whichever is sooner.
- Credit: with your permission, we credit you in the changelog and in the acknowledgments list below. We do not run a paid bounty programme; recognition is what we offer.
Encrypted submission
Our PGP public key is at /.well-known/openpgp-pubkey.asc. Fingerprint:
C7D3 1EAE 5E82 AE85 3FF2 B4C0 DB14 51FE 9044 C303
If you would rather not use PGP, say "encryption needed" in an initial unencrypted email and we will coordinate another channel.
What is in scope
- The Kelmscott macOS application, Direct or App Store build
- The Kelmscott CLI binary
- The Kelmscott Quick Look extension
- The licensing endpoint
- This website, kelmscott.app
What is out of scope
- Reports about third-party dependencies without evidence that Kelmscott's usage exposes the issue; report those upstream, and copy us if relevant
- Social-engineering attacks against operator email or accounts; do not attempt these
- Denial of service by flooding. If a small request amplifies into a large response, that is in scope; volume alone is not
- Self-XSS or attacks requiring the user's active collaboration
- Issues in pre-release builds, unless you can show they would survive to the stable release
Acknowledgments
Researchers who have helped harden Kelmscott will be credited here, with their permission. None yet; you could be the first.
The machine-readable counterpart to this page is /.well-known/security.txt (RFC 9116).
Last updated: 8 August 2026.