Vulnerability Disclosure Policy
Effective date: August 14, 2026
Project Research LLC values the work of independent security researchers. If you believe you’ve found a security vulnerability in the silverarrowapp.com website or the SilverArrow software, we want to hear about it. This page describes how to report it to us, what we ask of you while you do, and what you can expect from us in return.
1. Scope
In scope for this policy:
- The silverarrowapp.com website and its subdomains
- The SilverArrow browser extension (Chrome, Brave, Opera, Firefox, Safari) once released
- The SilverArrow mobile apps (Android, iOS) once released
- The SilverArrow desktop privacy browser for Windows, macOS, and Linux once released
Out of scope:
- Third-party services we merely link to or embed content from (Google Fonts, Imgur-hosted video, Discord, Instagram, X, YouTube, GoFundMe, and similar) — please report those directly to their respective owners
- Denial-of-service, spam, or social-engineering attacks against Project Research LLC, our team, or our users
- Findings that require physical access to a user’s device
- Automated scanner output with no demonstrated, exploitable impact
2. How to report
Email admin@projectresearchllc.com with a clear description of the issue. Please include:
- The URL, page, or software component affected
- Steps to reproduce, or a proof-of-concept
- The potential impact, as you understand it
- Your name or handle, if you’d like credit (optional — anonymous reports are accepted)
This mailbox is not monitored for general support requests. For anything other than a security report, please use our Contact page instead.
3. What we ask of you
- Give us a reasonable amount of time to investigate and remediate before disclosing the issue publicly
- Make a good-faith effort to avoid privacy violations, data destruction, and service disruption during your research
- Only interact with accounts and data you own, or with explicit permission from the account holder
- Do not exploit the vulnerability beyond what is necessary to demonstrate it
4. Safe harbor
Project Research LLC will not pursue legal action against researchers who discover and report vulnerabilities in good faith, in accordance with this policy. This safe harbor applies only to testing conducted consistent with Section 3 above and this policy’s scope. If a third party initiates legal action related to your research and you have complied with this policy, we will make it known that your actions were conducted in compliance with it.
5. What to expect from us
- Acknowledgment: we aim to confirm receipt of your report within 5 business days.
- Assessment: we’ll evaluate the report and let you know if we’re able to reproduce it and how we’re prioritizing it.
- Remediation: timelines vary with severity and complexity; we’ll keep you reasonably informed of progress.
- Coordinated disclosure: we ask for up to 90 days from acknowledgment before public disclosure, so a fix can ship first. We’re happy to discuss a different timeline for a specific finding.
6. Recognition
SilverArrow does not currently operate a paid bug bounty program. With your permission, we’re glad to credit you by name or handle once a reported issue is resolved.
7. Changes to this policy
We may update this policy as the SilverArrow product line grows past beta. The effective date above reflects the most recent revision.
This is a security-research policy, not a legal document governing your general use of the Site — see the Privacy Policy and Terms of Use for that. It is also distinct from our security.txt file, which points here.