Security and Vulnerability Disclosure
Effective April 18, 2026
Updated July 9, 2026
Security is foundational to Official Unofficial, Inc. ("Official Unofficial," "we," "us," or "our"). We welcome good-faith research that helps us keep our users and systems safe. This page sets out how to report vulnerabilities and what to expect from us, together with the terms under which we will not pursue legal action against researchers who follow this policy.
1. Purpose and Scope
This Vulnerability Disclosure Policy ("Policy") establishes a framework for reporting and resolving security vulnerabilities in the Services listed in Section 3. Nothing in this Policy authorizes activity that is illegal, that harms users, that targets our employees or third parties, or that falls outside the rules of engagement below. This Policy may be updated from time to time; please consult the "Last updated" date.
2. Safe Harbor
When you conduct vulnerability research in good faith in accordance with this Policy, we will:
- consider your research to be authorized under the Computer Fraud and Abuse Act (18 U.S.C. § 1030) and consistent with the U.S. Department of Justice's May 2022 policy regarding good-faith security research;
- consider your research to be authorized under any state computer access laws analogous to the CFAA;
- waive any restrictions in our Terms of Service or Acceptable Use policy that would otherwise prohibit the specific conduct necessary for good-faith security testing permitted by this Policy, for the limited purpose of that testing;
- not pursue or support any civil action or criminal complaint, and not make any referral to law enforcement, against you for your research;
- consider your research to be an "authorized" activity for the purpose of any anti-circumvention claim under the Digital Millennium Copyright Act (17 U.S.C. § 1201), to the extent consistent with the DMCA security-research exemption.
If legal action is initiated by a third party against you for activities that were, to the best of our judgment, conducted in good faith under this Policy, we will take steps to make it known that your actions were authorized. "Good faith" means research that is undertaken for the primary purpose of identifying and promptly reporting security issues, that avoids harm to users or the Services, and that complies with the rules in Section 7.
This safe harbor does not authorize activity against third-party systems that host or provide services to us; you remain responsible for complying with the terms and authorized-use policies of any such third party. If a vulnerability you discover involves a third-party system, please contact us and we will coordinate as appropriate.
3. In-Scope Targets
- the Uno iOS application as distributed through the Apple App Store;
- our production web properties, including officialunofficial.com and makechain.net, and their subdomains that we operate (including *.officialunofficial.com and *.makechain.net served from our infrastructure);
- our production API endpoints, including api.officialunofficial.com;
- the Makechain protocol contracts and infrastructure that we deploy or operate, identified on our developer site;
- associated authentication, session, and key-management systems, including the server-side signer-key infrastructure described in our Terms and Privacy Policy.
4. Out-of-Scope Targets and Findings
The following are out of scope under this Policy:
- third-party services, software, or infrastructure we do not operate (including Apple, our cloud providers, content delivery networks, wallet providers, public Farcaster hubs we do not operate, and public RPC endpoints);
- findings from physical testing or physical access to our offices, facilities, or devices;
- social-engineering attacks against employees, contractors, users, or vendors (including phishing, vishing, and pretexting);
- denial-of-service (volumetric, application-layer, or resource exhaustion) and load testing;
- findings that require a rooted, jailbroken, or otherwise significantly modified device;
- findings based solely on outdated software or library versions without a demonstrated, reproducible security impact;
- missing security headers, missing cookie flags, weak TLS ciphers, and similar "best-practice" findings without a demonstrated impact;
- self-XSS, clickjacking on pages with no sensitive actions, CSRF on unauthenticated endpoints or logout, rate-limiting absence on non-sensitive endpoints, and similar low-impact findings absent a demonstrated attack chain;
- content injection, reflected file download, tabnabbing, or UI redressing without a security impact;
- anything that requires unlawful access, destruction, or modification of data, or that causes harm to users.
5. Reporting a Vulnerability
Send reports to security@officialunofficial.com. If you would like to encrypt your report, request our PGP key by email and we will respond with the current public key fingerprint.
Please include the following in your report:
- a clear description of the vulnerability and its impact;
- the affected endpoint, asset, or code path, and the product name (Uno, Makechain, website, API);
- step-by-step reproduction instructions, including any accounts, IP addresses, payloads, or timestamps used;
- a minimal proof of concept (screenshots, cURL commands, short scripts);
- any suggested remediation, and your preferred contact information and preferred credit name, if any.
6. Our Commitments
- Acknowledgment. We will acknowledge your report within 72 hours of receipt.
- Triage. We will confirm or dispute the finding within 10 business days and assign a severity rating.
- Status updates. We will provide status updates at least every 10 business days until the issue is resolved or closed.
- Coordinated disclosure. Our standard coordinated disclosure window is 90 days from the acknowledgment date. We may request an extension for complex issues, and we may publish sooner for already-public issues or when a fix is deployed. We will work with you on the timing and content of any public disclosure.
- Credit. With your permission, we will credit you in our advisories or a public researcher acknowledgments list.
- No retaliation. We will not take retaliatory legal or administrative action against researchers operating in good faith under this Policy.
7. Rules of Engagement
- test only against accounts, tenants, and data that belong to you, or for which you have explicit permission from the account holder;
- stop testing and report immediately upon encountering user data that is not yours; do not access, download, modify, store, share, or exfiltrate such data beyond the minimum necessary to demonstrate the issue;
- use only non-destructive payloads and avoid any action that could degrade, disrupt, or damage the Services or harm users;
- do not use automated scanners in a way that generates significant traffic; where possible, throttle requests and identify yourself in a custom User-Agent (for example,
vdp-research/<handle>); - keep vulnerability details confidential until we agree on a disclosure plan;
- comply with all applicable laws, including export-control and sanctions laws, and with the terms of any third-party service implicated by your research.
8. Prohibited Conduct
Nothing in this Policy authorizes activity that is illegal or that would violate the rules in Section 7. In particular, this Policy does not authorize: accessing or modifying data that is not your own except to the minimum extent needed to demonstrate the issue; denial-of-service or resource-exhaustion attacks; social engineering; physical intrusion; extortion; payment demands as a condition of disclosure; or interaction with our employees, contractors, users, or vendors other than through the reporting channels in Section 5. Activity outside the authorization in this Policy is not covered by the safe harbor in Section 2.
9. Rewards
Official Unofficial does not currently operate a paid bug bounty. We publicly recognize researchers, with permission, in advisories or a researcher acknowledgments list, and we may provide swag or discretionary rewards for impactful findings. We may launch a formal bug bounty in the future and will announce the scope and reward scale separately.
10. Incident Response and Breach Notification
If we determine that a security incident has affected your personal information, we will notify you and the appropriate authorities as required by applicable law, including breach-notification deadlines under U.S. state law and, where applicable, Article 33/34 of the GDPR. Our notice will describe, to the extent known, the nature of the incident, the categories of information affected, the measures taken, and steps you can take.
11. Contact
For security reports, contact security@officialunofficial.com. For all other inquiries, contact legal@officialunofficial.com.
Official Unofficial, Inc.
Attn: Security
116 Remsen St.
Brooklyn, NY 11201
United States
© 2026 Official Unofficial, Inc. All rights reserved.