Skip to content
Scoplen

Security

Found a vulnerability? Tell us privately.

Write to scoplen-security@plystra.com. Do not open a public issue.

Reporting

Include
The affected part or version, what an attacker could do, and how to reproduce it.
Disclosure
Coordinated, with a 90-day default window.
Fixes
For the current and the previous minor version.
Bounty
None.

Design commitments

Device keys
Kept in the Secure Enclave or TPM wherever the device has one; never exported from it.
Sync
End-to-end encrypted. The server stores what it cannot read.
Tokens
Short-lived and bound to the device that obtained them.
Team access
SSH certificates that expire in minutes or hours, not long-lived keys.
Audit
Chained and signed, so changes and gaps can be detected.
Old algorithms
Off by default; enabled per host only.

Current status

Maturity
In development. Nothing to download yet. The pages describe the intended product.
Review
No independent review yet. Scoplen will not be labeled Stable before one is completed with no open high or critical findings.