Security
Security, in the open
Security is not a layer on top of our work — it is the work. The same people who build our platforms run our security program, publish every advisory, and answer every report.
Ribose operates as a CVE Numbering Authority, runs a coordinated disclosure program across all ribose.com properties, and maintains the OpenPGP tooling trusted by millions.
Portfolio
Security software we build
RNP
High-performance OpenPGP, used by Mozilla Thunderbird
4 repositoriesgithub.com/rnpgp
Confium
Multi-stakeholder threshold cryptography
4 repositoriesgithub.com/confium
Engyon
Document confidentiality and provenance for collaborative text
2 repositoriesgithub.com/engyon
Ammitto
Sanction screening from published sources
3 repositoriesgithub.com/ammitto
Cryptode
VPN connection management (CLI + macOS app)
2 repositoriesgithub.com/riboseinc
Retrace
Security vulnerability and bug discovery through behavior monitoring
1 repositoriesgithub.com/riboseinc
Bacman
UI tool for ISO 22301 business continuity management
2 repositoriesgithub.com/riboseinc
CVE Numbering Authority
Authorized by the CVE Program
Ribose is authorized as a CVE Numbering Authority (CNA) and publishes authoritative CVE records for its products and services into the CVE List, which feeds the U.S. National Vulnerability Database.
3published advisories
Coordinated disclosure
Responsible Security Disclosure Program
We believe in responsible disclosure and ask that you allow us time to investigate and patch before publishing details — verification and testing can take from several hours to several days. We actively work with security researchers and participate inBugcrowd's bug bounty program. Every report gets a response.
To be considered, a report must
- Be verifiable, with as much detail as possible — browser, platform, and a video are greatly appreciated
- Be the first report of the issue; the earliest submission counts
- Describe an actual bug — improvement suggestions are welcome but do not qualify
- Not negatively impact other users (e.g. no unsolicited XSS messages)
- Not use automated scanners, DDoS, or capacity testing
Scope and recognition
- Scope: any Ribose subdomain (*.ribose.com); third-party services operating a subdomain are excluded
- Valid examples: authentication flaws, XSS, CSRF/XSRF, server-side code execution, SQL injection, directory traversal, stack traces
- Not valid: reCAPTCHA, raw scanner output without a proof of concept, IP leaks, SSL-setting findings, clickjacking-only issues, logout CSRF
- Accepted reports receive a swag kit and a place in the Security Hall of Fame
Our security team has the final say on whether a report qualifies as a vulnerability. Not a security issue? Use the feedback form.
Report a vulnerability
security.reports@ribose.com
OpenPGP-encrypted reports are welcome and preferred.