Security Policy

At BTOVEN NETWORK, we take security seriously. We appreciate the work security researchers do to help keep our services safe for everyone.

Reporting a Vulnerability

If you discover a security vulnerability in any of our services, please report it to us through our IRC channel:

For sensitive information, please encrypt your message using our PGP key available at /pgp-key.asc

Guidelines for Responsible Disclosure

When reporting vulnerabilities, please:

  • Provide sufficient information for us to reproduce and verify the vulnerability
  • Include steps to reproduce, proof-of-concept, or screen captures if applicable
  • Respect user privacy and do not access or modify user data
  • Allow us reasonable time to fix the issue before disclosing publicly
  • Avoid performing actions that could cause service disruption or data loss

What We Ask of You

  • Don't exploit the vulnerability beyond what's necessary to demonstrate it
  • Don't access, modify, or delete data that's not yours
  • Don't disrupt our services or services for other users
  • Follow responsible disclosure principles

What You Can Expect from Us

  • Acknowledgment of your report within 48 hours
  • Regular updates on our progress in fixing the issue
  • Transparency about our remediation timeline
  • Credit in our security acknowledgments (if you wish)
  • Consideration for a bounty or reward for critical vulnerabilities (at our discretion)

Safe Harbor

If you follow these guidelines, we will not take legal action against you in response to your security research. We consider security research conducted in accordance with this policy to be authorized and we will not pursue legal action.

In-Scope Services

Productivity Tools

  • tasks.btoven.net
  • translate.btoven.net
  • resume.btoven.net
  • pdf.btoven.net

Utilities

  • tools.btoven.net
  • paste.btoven.net
  • ntfy.btoven.net

Privacy & Security

  • searxng.btoven.net
  • pgp.btoven.net
  • wkd.btoven.net
  • dane.btoven.net

Infrastructure

  • btoven.net
  • status.btoven.net

Out of Scope

  • Third-party services integrated into our platforms
  • Social engineering attacks
  • Physical attacks on our infrastructure
  • Vulnerabilities in browsers or client-side software
  • DDoS attacks or service disruption
  • Issues already known or publicly disclosed

Contact Information

For security-related inquiries, please use our dedicated security channel:

For sensitive information, please use our PGP key: /pgp-key.asc

This policy was last updated on April 15, 2026. For the most current information, please check our security.txt file at /.well-known/security.txt