Every fix has a first reporter. This page names them.
Security researchers who find something in eclean and tell us privately get two things, a fast fix, and their name here for as long as this company exists.
This line is reserved.
No one has reported a vulnerability in eclean yet. Either we’ve been careful, or nobody has looked properly. We’d genuinely like to know which.
How a name gets here. Coordinated disclosure, in the order it happens.
- 1
Report it privately
Mail security@eclean.gg, encrypted with our PGP key if it’s sensitive. No forms and no triage portal. A person reads it.
- 2
Give us time to fix
Coordinated disclosure means we confirm what you found, ship the fix, and agree on timing before anything goes public.
- 3
Leave user data alone
Test against your own machine and your own account. If proving the bug would touch someone else’s data, stop and tell us instead.
- 4
Take the credit
Name, link, date, and what you found, published with your sign-off. An alias is fine. So is staying anonymous.
We don’t run a paid bug bounty yet, and we won’t pretend otherwise. What we promise instead is a fast fix, a straight answer, and credit that doesn’t expire.
Rather not say it in plaintext? Neither would we.
The PGP page carries our key, its full fingerprint, and the three gpg commands from finding something to telling us safely.
Get the PGP key