Security
Found a vulnerability? Tell us privately.
Write to scoplen-security@plystra.com. Do not open a public issue.
Reporting
- Address
- scoplen-security@plystra.com
- Include
- The affected part or version, what an attacker could do, and how to reproduce it.
- Disclosure
- Coordinated, with a 90-day default window.
- Fixes
- For the current and the previous minor version.
- Bounty
- None.
Design commitments
- Device keys
- Kept in the Secure Enclave or TPM wherever the device has one; never exported from it.
- Sync
- End-to-end encrypted. The server stores what it cannot read.
- Tokens
- Short-lived and bound to the device that obtained them.
- Team access
- SSH certificates that expire in minutes or hours, not long-lived keys.
- Audit
- Chained and signed, so changes and gaps can be detected.
- Old algorithms
- Off by default; enabled per host only.
Current status
- Maturity
- In development. Nothing to download yet. The pages describe the intended product.
- Review
- No independent review yet. Scoplen will not be labeled Stable before one is completed with no open high or critical findings.