Security and responsible disclosure
Last updated 8 October 2026
We build security tools, so we want to hear about problems in them. If you find a vulnerability, please tell us privately first.
1. How to report
Email hello@leakybyte.xyz with the subject Security report. Include what you found, the steps to reproduce it, the version or commit, and the impact you see. A short proof of concept is ideal.
Please do not open a public issue for a vulnerability before we have had a chance to fix it. Our contact details are also published in security.txt.
2. What is in scope
- The code at https://github.com/tcvdh/leakybyte, including the detection engines, the Veil proxy, the command line tool and Plug.
- The website at leakybyte.xyz.
- Especially welcome: a way to make Veil send a value it should have redacted, to make Plug let a data-stealing link or hidden text through, or to forge or evade a Canary check.
3. What we ask of you
- Test only against your own setup and data, or the public website without disrupting it.
- Do not access, change or keep other people's data, and do not run denial-of-service or social-engineering attacks.
- Give us a reasonable time to fix the issue before you publish details.
4. What you can expect from us
- We aim to acknowledge your report within 7 days and to keep you updated until it is fixed.
- We will not take legal action against research done in good faith under this policy.
- We will credit you in the fix notes if you want us to.
- We are a very small project and cannot offer a paid bounty at this time.
5. Known limits
Our tools are heuristic by design. Veil cannot see names or addresses, and Plug is one layer of defence rather than a guarantee. Those limits are documented on each product page and are not vulnerabilities, but reports of ways around the documented checks are welcome.