← rununtil.com

Security Policy

Vulnerability disclosure policy of RunUntil Technologies GmbH

Reporting a vulnerability

We take security reports seriously. If you believe you have found a security vulnerability in any product or service operated by RunUntil Technologies GmbH, please report it to:

Please include a description of the issue, steps to reproduce, affected product and version, and any proof-of-concept material. Encrypted reports are welcome; request our PGP key via the address above if needed.

Our response process

Browser products

For our Chromium-based browser products, we track the upstream Chromium project's security releases and ship corresponding updates promptly. Vulnerabilities fixed in our releases, including applicable CVEs inherited from upstream Chromium, are published on our security releases page, mapping each vulnerability to the first fixed product version.

Issues in upstream Chromium itself are best reported directly to the Chromium security team; we coordinate with upstream where appropriate.

Scope and safe harbor

We will not pursue legal action against researchers who, in good faith:

We are happy to credit reporters in our release notes unless you prefer to remain anonymous.