LeakyByte

Security and responsible disclosure

Last updated 8 October 2026

We build security tools, so we want to hear about problems in them. If you find a vulnerability, please tell us privately first.

1. How to report

Email hello@leakybyte.xyz with the subject Security report. Include what you found, the steps to reproduce it, the version or commit, and the impact you see. A short proof of concept is ideal.

Please do not open a public issue for a vulnerability before we have had a chance to fix it. Our contact details are also published in security.txt.

2. What is in scope

  • The code at https://github.com/tcvdh/leakybyte, including the detection engines, the Veil proxy, the command line tool and Plug.
  • The website at leakybyte.xyz.
  • Especially welcome: a way to make Veil send a value it should have redacted, to make Plug let a data-stealing link or hidden text through, or to forge or evade a Canary check.

3. What we ask of you

  • Test only against your own setup and data, or the public website without disrupting it.
  • Do not access, change or keep other people's data, and do not run denial-of-service or social-engineering attacks.
  • Give us a reasonable time to fix the issue before you publish details.

4. What you can expect from us

  • We aim to acknowledge your report within 7 days and to keep you updated until it is fixed.
  • We will not take legal action against research done in good faith under this policy.
  • We will credit you in the fix notes if you want us to.
  • We are a very small project and cannot offer a paid bounty at this time.

5. Known limits

Our tools are heuristic by design. Veil cannot see names or addresses, and Plug is one layer of defence rather than a guarantee. Those limits are documented on each product page and are not vulnerabilities, but reports of ways around the documented checks are welcome.