Skip to content

Security

Security, in the open

Security is not a layer on top of our work — it is the work. The same people who build our platforms run our security program, publish every advisory, and answer every report.

Ribose operates as a CVE Numbering Authority, runs a coordinated disclosure program across all ribose.com properties, and maintains the OpenPGP tooling trusted by millions.

Portfolio

Security software we build

CVE Numbering Authority

Authorized by the CVE Program

Ribose is authorized as a CVE Numbering Authority (CNA) and publishes authoritative CVE records for its products and services into the CVE List, which feeds the U.S. National Vulnerability Database.

3published advisories

Coordinated disclosure

Responsible Security Disclosure Program

We believe in responsible disclosure and ask that you allow us time to investigate and patch before publishing details — verification and testing can take from several hours to several days. We actively work with security researchers and participate inBugcrowd's bug bounty program. Every report gets a response.

To be considered, a report must

  • Be verifiable, with as much detail as possible — browser, platform, and a video are greatly appreciated
  • Be the first report of the issue; the earliest submission counts
  • Describe an actual bug — improvement suggestions are welcome but do not qualify
  • Not negatively impact other users (e.g. no unsolicited XSS messages)
  • Not use automated scanners, DDoS, or capacity testing

Scope and recognition

  • Scope: any Ribose subdomain (*.ribose.com); third-party services operating a subdomain are excluded
  • Valid examples: authentication flaws, XSS, CSRF/XSRF, server-side code execution, SQL injection, directory traversal, stack traces
  • Not valid: reCAPTCHA, raw scanner output without a proof of concept, IP leaks, SSL-setting findings, clickjacking-only issues, logout CSRF
  • Accepted reports receive a swag kit and a place in the Security Hall of Fame

Our security team has the final say on whether a report qualifies as a vulnerability. Not a security issue? Use the feedback form.

Report a vulnerability

security.reports@ribose.com

OpenPGP-encrypted reports are welcome and preferred.

Email the security team
esc
navigate   openSearch by Pagefind