← Home

Bug Bounty Program

Complete reports enter technical triage. Good-faith research receives Safe Harbor.

1. Overview

Perpetua Labs LLC operates the Cryptograph bug bounty program. We review valid security findings against the Cryptograph wallet on watchOS, the companion iPhone app, our recovery formats, and our backend infrastructure. We may grant discretionary awards of up to $5,000 USD for reports that meet the monetary eligibility requirements below.

Report completeness, validity, severity, remediation priority, and monetary eligibility are separate decisions. Sending a message does not create an entitlement to technical investigation, remediation, or an award.

Send reports to security@cryptograph.watch. We acknowledge receipt within 3 business days. Complete submissions enter initial triage within 7 business days. Good-faith research conducted under the rules below is authorized under our Safe Harbor commitment.

Policy version 2.1. Effective 2026-09-05. This revision applies only to reports first received on or after that date. We handle earlier reports under the policy and written representations in effect when they were submitted. We will not retroactively reclassify an earlier report or reduce an approved award under this revision.

2. Scope

In scope

Out of scope

Monetary award eligibility

A standard monetary award requires an in-scope finding with a realistic exploitation path that affects a supported release and is capable of causing user harm. The report must identify the affected artifact, reproduce the vulnerable behavior, explain attacker preconditions, and connect the behavior to confidentiality, integrity, authorization, recovery, or fund safety.

A supported release is a Cryptograph version that Perpetua Labs publicly distributes through the App Store or another official public channel and identifies as supported when the report is submitted. The vulnerable behavior must be present in that release. A report may also qualify when it documents a credible route from the finding to harm users of such a release.

Findings limited to an unreleased branch, a source snapshot, or a non-public pre-release test build may be submitted. They enter technical triage only when the report includes a working reproduction and documents a credible route to harm users of a publicly distributed supported release. We may review other source observations at our discretion.

Publication, mirroring, merging, synchronization, or automated scanning of source code alone does not make a finding reward-eligible. These events do not establish release exposure or user harm by themselves.

A finding that requires prior compromise of iOS, watchOS, the Secure Enclave, or the user's device generally does not qualify for a monetary award. An exception applies when the report also shows that Cryptograph independently violates a security boundary we published or expressly promised. Examples include signing material reaching the iPhone, the watch signing a transaction other than the one it showed the user, or Cryptograph code bypassing its stated Secure Enclave-backed protection of the recovery mnemonic. Compromise of an Apple platform or device alone remains out of scope.

Excluded from rewards

The following are not eligible for monetary payout. We may acknowledge and close them at intake without technical investigation:

3. Severity classification

We assign severity after a report passes intake and its security impact is reproduced. Reporter-supplied labels, CVSS scores, and urgency language do not affect queue priority. We use CVSS 4.0 with the wallet-specific examples below as guidance.

4. Rewards

The table provides award guidelines after a report separately meets the monetary eligibility requirements. Every award and amount remains at Perpetua Labs's discretion. The listed figures are maximums, not automatic payments.

Tier Maximum (USD) Definition and examples
Critical $5,000 Fund-loss / private-key extraction / mass exploitation across users.

Examples: extraction of signing material from the watch through Cryptograph code; arbitrary unauthorized signing; transaction substitution post-confirmation; Recovery Sheet decryption without its PIN or passphrase; mass user-fund loss path.
High $1,000 Significant security degradation; partial fund loss; account compromise without full key access.

Examples: Photo Backup decryption without its PIN or passphrase; iPhone↔watch protocol downgrade allowing tx tampering; partial key disclosure (≤16 bytes of mnemonic entropy); verified-contract registry signature bypass.
Medium $250 Meaningful security degradation requiring user interaction or specific conditions.

Examples: address-display spoofing on the watch; recovery-format collision under attacker control; nonce manipulation requiring user co-operation; backend cache poisoning that changes non-critical metadata shown in the app.
Low $100 A reproducible security-boundary failure with limited impact.

Hardening suggestions, theoretical side channels, and behavior differences without demonstrated security impact do not qualify.

Program terms

5. Submission rules

6. Triage and disclosure timeline

7. Sanctions and KYC

Perpetua Labs LLC is a US-domiciled company subject to US sanctions law. To remain in compliance with the Office of Foreign Assets Control (OFAC) and applicable US tax law, we apply the following payout requirements:

8. Safe Harbor

Perpetua Labs LLC (the “Company”) commits to the following Safe Harbor for security researchers who comply with this policy. This language is adopted from the disclose.io core terms (MIT-licensed; pulled 2026-05-03).

Safe Harbor and our non-retaliation commitments do not depend on report completeness, validity, severity, monetary eligibility, or payment. Acknowledgement and Safe Harbor do not guarantee technical review.

Authorization

If you make a good-faith effort to comply with this policy during your security research, we will consider your research to be authorized. Perpetua Labs LLC will not recommend or pursue legal action related to your research. We work with researchers to understand and resolve complete reports accepted into technical triage.

Anti-litigation pledge

To the extent that your security research activities are inconsistent with certain restrictions in our applicable Terms of Service, we waive those restrictions for the limited purpose of permitting security research under this policy. Should legal action be initiated by a third party against you for activities that were conducted in accordance with this policy, we will take steps to make it known that your actions were conducted in compliance with this policy.

ToS waiver

Activities conducted in a manner consistent with this policy are not considered to violate our Terms of Use, our Privacy Policy, the App Store and Apple Developer terms, the US Computer Fraud and Abuse Act (CFAA), the DMCA §1201 anti-circumvention provisions, or analogous computer-misuse laws in other jurisdictions, to the extent of our ability to commit on your behalf.

Good-faith standard

We define “good-faith security research” consistent with the disclose.io Good Faith Security Research standard. In summary, you act in good faith if you:

Source: disclose.io core terms, MIT-licensed. Pulled 2026-05-03 from github.com/disclose/diodb. Adapted with Perpetua Labs LLC named as the committing entity and Cryptograph as the named product. Material public-policy revisions are gated on security and legal review before publication.

9. How to report

Where to send

Required intake evidence

A suggested CVSS 4.0 vector is optional. Length, formatting, and repeated severity labels do not substitute for evidence.

What NOT to include


Have a finding? Email security@cryptograph.watch. For architecture context, see the Technical Security Overview.

Policy version 2.1. Effective 2026-09-05. Material revisions receive security and legal review before publication.