Security
Reporting a vulnerability
Thank you for looking. Please report privately first.
Email security@voxterrae.app with the version, the networks involved, steps to reproduce and impact. You will get an acknowledgement within 72 hours and a fix or a timeline within 14 days for anything that affects message confidentiality, certificate handling or remote code execution. Please give us that window before publishing.
Scope
- The VoxTerrae client (this site's downloads and the source).
- This website and its feeds.
- Out of scope: the EFnet servers (not ours), and social-engineering of channel members.
What we already do
- Strict CA verification on HOME; trust-on-first-use pinning with change refusal on EFnet.
- Published SHA-256 for every file; SHA256SUMS per release.
- No third-party code on this site; no telemetry in the client.
Machine-readable
/.well-known/security.txt (RFC 9116).