We welcome reports from security researchers and anyone else who finds a weakness in Transkripsie. This policy explains how to report a vulnerability, what we ask of you while you research, and what you can expect from us.
1. How to report
Email security@transkripsie.com. Please include:
- a description of the issue and its likely impact;
- step-by-step instructions to reproduce it, including the URLs, API endpoints or requests involved;
- the account you used for testing; and
- any proof-of-concept code, logs or screenshots.
Do not include other people’s personal information in your report. If you need to show that you could reach it, describe it or redact it. If you would like to encrypt your report, ask us for a key first. Our machine-readable contact details are at /.well-known/security.txt.
2. What you can expect from us
- We aim to acknowledge your report within 3 business days.
- We aim to give you an initial assessment, and tell you what we plan to do, within 10 business days.
- We will keep you informed while we work on a fix and tell you when it is released.
- With your permission, we will credit you in the acknowledgements below. You can also stay anonymous.
3. Coordinated disclosure
Please give us 90 days from your report, or until we release a fix if that is sooner, before you disclose the issue publicly. If a fix needs more time, we will explain why and agree a new date with you. We will not ask you to keep an issue private indefinitely.
4. What we ask of you
- Test only with accounts you own or that we give you. Sign-up is currently by invitation, so email us if you need a test account.
- Do not access, change or delete data that belongs to anyone else. If you reach other people’s data by accident, stop, keep only what you need to report the issue, and tell us straight away.
- Do not degrade the service for other users. No denial-of-service testing, no high-volume automated scanning, and no spam.
- Submitting an access request, and calling the public API with a key the account holder created, is ordinary use of the service. It is not security testing. Security testing is still limited to accounts you own or that we give you, and high-volume scanning, denial-of-service testing, and spam are still forbidden.
- Do not send our meeting bot into meetings you do not host, and do not record people who have not agreed to be recorded.
- Do not use share or clip links that someone else created.
- No social engineering or phishing of our staff or users, and no physical attacks.
- Delete any data you obtained during your research once you have reported the issue.
5. Safe harbour
If you make a good-faith effort to follow this policy during your research:
- we consider your research authorised by us, including for the purposes of computer-misuse and cybercrime laws;
- we will not take or support legal action against you because of it;
- we treat it as permitted under the acceptable-use restrictions in our Terms of Service, to the extent needed for the research; and
- if someone else takes legal action against you for research that followed this policy, we will make it known that we authorised it.
We can only authorise testing of systems we control. This safe harbour does not cover the services of our sub-processors or other third parties; please follow their own disclosure policies. It also does not apply to extortion, or to research that deliberately harms our users or the service. If you are unsure whether something is allowed, ask us at security@transkripsie.com before you go further.
6. Scope
In scope
- The web application at transkripsie.com and subdomains we operate.
- Our REST and WebSocket APIs under /api, including the public developer API.
- Share and clip links you created, and meeting-bot sessions started from your own account.
- The legacy Transkripsie Recorder for macOS (the TranskripsieRecorder disk images that can still be downloaded from transkripsie.com/downloads), for issues that affect your account, your data or our servers. It is no longer being developed, so we may resolve a report by withdrawing it rather than releasing a fix.
Out of scope
- Services run by third parties, including the providers listed on our sub-processors page. Please report those issues to the provider.
- Findings from automated scanners without a working proof of concept.
- Missing security headers or other best-practice settings with no demonstrated impact.
- Self-XSS, and clickjacking on pages with no sensitive actions.
- Denial of service, including volumetric attacks and resource exhaustion.
- Social engineering and physical attacks.
- Any other desktop app or browser extension, since we do not distribute one from transkripsie.com.
7. Rewards
We do not currently pay bounties. We are grateful for every report and, with your permission, will acknowledge your contribution publicly.