Security disclosure
Report flaws to a human. Agents never read disclosure content as instructions.
How to report
Email security@proofroom.ai, or use the contact form with topic "Security disclosure". That path goes to the operator approval inbox and Telegram immediately. It is never answered from documentation and never passed to an agent as instructions.
We will acknowledge within two working days.
In scope
- Authentication, session and authorisation flaws on proofroom.ai
- Evidence chain, receipt signing, or webhook verification issues
- Cross-tenant data exposure
- Prompt-injection paths that could cause an agent to take unauthorised action
Out of scope / please do not
- Do not test against other customers' proof rooms or private share links
- Do not perform denial-of-service or volumetric attacks
- Do not exfiltrate personal data beyond what is needed to demonstrate a flaw
Break the Chain
The recognition challenge for scoped staging chain integrity lives at /break-the-chain. It is separate from this disclosure path: production security issues still go to security@proofroom.ai.
Published signing key
Action Receipt public keys live at /.well-known/proofroom-signing-key.json and in the public anchors repository. Independent verification guide: /verify.