sessiontwin

Security & Vulnerability Disclosure

Last updated: 30 July 2026 · Draft for review

Draft — for review. sessiontwin is a product about verifiability; it should have a clear route for reporting security problems. The contact address and any reward policy are for the operator to finalise.

Reporting a vulnerability

If you believe you have found a security vulnerability, please report it privately to [security contact — TO BE SUPPLIED, e.g. security@sessiontwin.ai]. Please include enough detail to reproduce the issue and give us a reasonable time to fix it before any public disclosure.

What to expect

Scope and safe harbour

In-scope: sessiontwin.ai and the sessiontwin application. Out of scope: the underlying Base44/Wix platform, GitHub, and other third-party services — report those to the respective providers. Please act in good faith: do not access or modify other users' data, do not degrade the service, and do not run automated attacks. We will not pursue good-faith researchers who follow this policy.

How the product is built to be checkable

sessiontwin's ledger is signed with a key the backend never holds, and its integrity can be audited independently in the browser — see the ledger page. Note that integrity evidence proves a record was not altered; it does not prove the work is correct or secure (see the Terms, "What a verified ledger does — and does not — attest").

Known items under review

As part of preparing these documents, the following were flagged for the operator to verify (details in the internal review report):

Open questions for counsel / operator

  1. Finalise the security contact address and publish it.
  2. Decide whether to offer a /.well-known/security.txt file (recommended) pointing here.
  3. Confirm the safe-harbour wording is compatible with Israeli law.