Last updated: May 2026
Attomus builds security-critical software. We take vulnerability reports seriously and are committed to working with researchers in good faith. This policy describes how to report a security issue and what you can expect from us.
Scope
This policy covers all Attomus products and services, including:
- Attomus Signet — iOS and Android authenticator application
- AttomusOTP — open-source Swift and Kotlin OTP library
- SemaFore — secure business messaging platform (iOS, Android, and web clients; server infrastructure)
- attomus.com — this website and associated infrastructure
If you are unsure whether something is in scope, report it anyway. We would rather investigate a non-issue than miss a genuine finding.
How to report
Email security@attomus.com.
Please include:
- A clear description of the vulnerability
- The product and version affected
- Steps to reproduce, or a proof-of-concept where safe to provide
- The potential impact as you understand it
- Your name or handle (optional — anonymous reports are accepted)
If you believe the issue is sensitive, you may encrypt your report using our PGP key. Contact hello@attomus.com to request it.
What we commit to
Acknowledgement. We will acknowledge receipt of your report within 48 hours.
Assessment. We will provide an initial assessment — confirming whether we can reproduce the issue and whether we consider it in scope — within 7 days.
Updates. We will keep you informed of progress at reasonable intervals. If we need more information from you, we will ask.
Resolution. We aim to remediate confirmed vulnerabilities within 90 days of the initial report. Critical issues affecting user security are prioritised and addressed as quickly as possible. We will let you know when a fix is released.
Credit. With your permission, we will acknowledge your contribution under security acknowledgements.
Safe harbour
Attomus will not pursue legal action against researchers who:
- Report vulnerabilities in good faith under this policy
- Do not access, modify, or exfiltrate data beyond what is necessary to demonstrate the issue
- Do not exploit a vulnerability for purposes other than demonstrating it to us
- Do not disclose the vulnerability publicly before we have had a reasonable opportunity to address it
We ask for a minimum of 90 days before public disclosure. If you believe a vulnerability is being actively exploited, contact us immediately and we will treat it as a critical issue.
Out of scope
The following are outside the scope of this policy:
- Social engineering attacks against Attomus staff or clients
- Physical attacks against Attomus premises or hardware
- Denial-of-service attacks
- Vulnerabilities in third-party software that we do not control, except where they directly affect an Attomus product
- Issues in products that have been publicly end-of-lifed
No bug bounty
We do not currently operate a paid bug bounty programme. We are grateful for all good-faith reports and will acknowledge contributions with the researcher’s consent.