A network. Not a platform. But still: a service, with an attack surface.
Security disclosure
If you've found a vulnerability in this TP Social registry, the desktop client, or the protocol implementation, we want to hear about it. We respond to reports promptly, credit researchers who ask to be credited, and never pursue good-faith research.
How to report
Email hello@tpsocial.net with "security" in the subject. Include reproduction steps and an estimate of impact. A signed PGP message is welcome but not required.
A machine-readable copy of this policy lives at
/.well-known/security.txt
per RFC 9116.
Scope
In scope:
- The registry shell and admin panel.
- The handle-resolve and page-publish endpoints.
- The desktop client's signing and pairing flows.
- Protocol bugs that let one identity be impersonated.
Out of scope:
- Reports generated solely by automated scanners with no proof of impact.
- Missing security headers or cookie flags that do not lead to exploitation given our threat model.
- Issues in third-party services we link to but do not operate (e.g. GitHub Releases, your email provider).
- Self-XSS or social-engineering attacks that require tricking the victim into running code locally.
Safe harbour
We will not pursue legal action against researchers who access only the data necessary to demonstrate a finding, avoid degradation of the service, and report through this channel before any public disclosure. Please give us a reasonable window to fix — 90 days for high-severity, shorter when there is active exploitation.