Security and vulnerability reporting
Report a security vulnerability, or a case where ChronoVerify returns an incorrect C2PA validation result, to support@chronoverify.com. Put SECURITY or CONFORMANCE in the subject line and it will be triaged ahead of ordinary support.
What to report
- Security vulnerabilities in the API, the web verifier, the MCP server, or the signed report format. Authentication and billing bypasses, injection, server-side request forgery, and anything that would expose another customer's data are the highest priority.
- C2PA validation non-conformance. A case where ChronoVerify's validation result disagrees with the C2PA Content Credentials specification. The clearest form of this is an image we accept that should have been rejected, or one we report as carrying no Content Credentials when it does.
- Signed report integrity. Any way to make a ChronoVerify signed audit record verify against content it does not describe.
What to include
The image or a link to it, the exact request you made, what ChronoVerify returned, and what you expected instead. For a validation disagreement, the output of another C2PA validator on the same file is the single most useful thing you can attach. Reports are accepted in English.
What happens next
- Acknowledgement within 72 hours of receipt, to a human-written reply rather than an autoresponder.
- An assessment of whether the report reproduces, and if so a remediation plan with a target date.
- For a confirmed C2PA non-conformance, remediation, and notification to the C2PA Conformance Program where our agreement with them requires it.
- Credit in the fix note if you want it, and not if you do not.
Safe harbour
If you make a good-faith effort to comply with this policy during your research, we will treat it as authorised, we will work with you to resolve the issue quickly, and we will not pursue legal action against you. Please do not access or modify data belonging to anyone else, do not degrade the service for other users, and give us a reasonable opportunity to fix an issue before disclosing it publicly.
Out of scope
Missing security headers with no demonstrated impact, reports generated by a scanner with no working proof of concept, denial of service through sheer volume, and social engineering of the operator or of any provider we use. Rate limits and upload size caps are deliberate; hitting one is not a vulnerability.
What ChronoVerify does not claim
ChronoVerify is an independent product and does not hold SOC 2 or ISO 27001 certification. There is no paid bug bounty. This page describes what we will actually do, which is respond quickly and fix what is real.
Machine-readable
The same contact information is published at /.well-known/security.txt in the RFC 9116 format.