generated: '2026-08-29' method: searched source: https://raw.githubusercontent.com/aranya-project/.github/main/SECURITY.md, https://spideroak.com/security-response/ provider: SpiderOak program_published: true note: 'probe-security-programs.py found nothing automatically because SpiderOak serves no /.well-known/security.txt and runs no HackerOne/Bugcrowd/Intigriti program. The policy is real, it is just published at ordinary paths. Upgraded to method: searched from the two documents below.' policies: - name: Aranya Project Security Policy url: https://github.com/aranya-project/.github/blob/main/SECURITY.md raw: https://raw.githubusercontent.com/aranya-project/.github/main/SECURITY.md status: 200 last_updated: 10OCT2024 contact: securityreports@spideroak.com scope: The Aranya open-source platform reporting: Private email; public GitHub issues explicitly forbidden for vulnerabilities. coordinated_disclosure: true embargo: Requests "a reasonable amount of time to resolve the issue before any disclosure"; reserves the right to disclose before resolution if appropriate. supported_versions: The latest version or release is supported. handling_process: - Confirm the problem and determine affected versions - Audit code for similar problems - Prepare fixes for all still-supported releases - Release security fix versions and update the public repository requested_report_fields: - Description of the vulnerability - Aranya software version, hardware platform and OS version - Logs and artifacts - Steps to reproduce - Potential impact - Suggested mitigation or fix - Reporter name/handle for credit credit_offered: true - name: SpiderOak Security Response url: https://spideroak.com/security-response/ status: 200 scope: SpiderOak products (ONE, Groups, CrossClave, Semaphor) response_time: Usually within 24 hours, certainly within 1 business day. pgp: A public key is offered for encrypting sensitive reports. credit_offered: true published_advisories: - date: '2017-09-28' summary: SpiderOak ONE and Groups v6.4.0 — Share Room vulnerabilities. - date: '2017-06-05' summary: SpiderOak ONE and Groups v6.3.0 — potential active attack vectors found by security researchers. defect_found: 'The contact address printed on this page is security@spideroak21.wpengine.com — a WP Engine staging hostname leaked into production copy, not a deliverable SpiderOak address. The working contact is securityreports@spideroak.com from the Aranya SECURITY.md. Worth reporting to the provider: a security company''s security-report address currently points at its hosting provider''s staging domain.' bug_bounty: exists: false note: No HackerOne, Bugcrowd or Intigriti program found; no paid bounty is advertised on either policy page. security_txt: exists: false probed: - url: https://spideroak.com/.well-known/security.txt status: 404 - url: https://spideroak.one/.well-known/security.txt status: 404 - url: https://aranya-project.github.io/.well-known/security.txt status: 404 note: RFC 9116 security.txt would be a near-zero-cost addition given the policy already exists. supply_chain: note: The Aranya repos carry a supply-chain/ directory (cargo-vet) and a published vet specification at https://aranya-project.github.io/vet/, plus release security controls at https://aranya-project.github.io/release-security-controls/ covering branch protections, CI/CD workflows, environment protections and secrets management. advisories_consumed: - id: RUSTSEC-2026-0007 action: v4.1.1 patch release (2026-02-03) cut as a defensive measure; Aranya code does not directly trigger the vulnerable path. url: https://rustsec.org/advisories/RUSTSEC-2026-0007