ChronoVerify

Security and vulnerability reporting

Report a security vulnerability, or a case where ChronoVerify returns an incorrect C2PA validation result, to support@chronoverify.com. Put SECURITY or CONFORMANCE in the subject line and it will be triaged ahead of ordinary support.

What to report

What to include

The image or a link to it, the exact request you made, what ChronoVerify returned, and what you expected instead. For a validation disagreement, the output of another C2PA validator on the same file is the single most useful thing you can attach. Reports are accepted in English.

What happens next

Safe harbour

If you make a good-faith effort to comply with this policy during your research, we will treat it as authorised, we will work with you to resolve the issue quickly, and we will not pursue legal action against you. Please do not access or modify data belonging to anyone else, do not degrade the service for other users, and give us a reasonable opportunity to fix an issue before disclosing it publicly.

Out of scope

Missing security headers with no demonstrated impact, reports generated by a scanner with no working proof of concept, denial of service through sheer volume, and social engineering of the operator or of any provider we use. Rate limits and upload size caps are deliberate; hitting one is not a vulnerability.

What ChronoVerify does not claim

ChronoVerify is an independent product and does not hold SOC 2 or ISO 27001 certification. There is no paid bug bounty. This page describes what we will actually do, which is respond quickly and fix what is real.

Machine-readable

The same contact information is published at /.well-known/security.txt in the RFC 9116 format.