Abditex
Security disclosure
If you've found a vulnerability in an Abditex app, server, website, or pipeline, please tell us before you tell anyone else. We treat security reports as the most important email in our inbox.
How to report
Email security@abditex.com. Encrypt the report with the PGP key below if the contents are sensitive.
Include: a description of the issue, steps to reproduce, the affected component (app version, server endpoint, pipeline path, or website page), and the impact you've observed or believe is possible. Proof-of-concept code is welcome but not required.
PGP key
User ID: Abditex Security <security@abditex.com>
Fingerprint: A09E 8EC1 B3DE EF8B 9505 5DF4 5A59 7390 A1A3
Algorithm: Ed25519 (signing). Created 2026-05-10, expires 2029-05-09.
Key file: /security/pgp.asc
Verify before encrypting to it: compare the fingerprint above against gpg --fingerprint security@abditex.com after import. The same fingerprint is used to sign the warrant-canary statement on the transparency page.
Response timeline
- Acknowledgment within 7 days. A real human reads every report and replies, even if only to say we've received it and are investigating.
- Critical-severity issues addressed within 90 days. Issues that compromise user data confidentiality, sync E2EE properties, attestation, or license enforcement.
- Lower-severity issues addressed within 180 days. Issues with limited blast radius or requiring unusual preconditions.
If we miss a target, we'll tell you why and give you a revised date. We won't ghost you.
Scope
In scope:
- The Abditex Bullion mobile app (iOS and Android).
- The API at
api.abditex.comand any subpath. - This website (
abditex.com) and its assets. - The ontology pipeline and AbditexOntologyBot behavior.
- Build, signing, and release infrastructure where it affects shipped artifacts.
Out of scope:
- Social engineering of Abditex staff or contractors.
- Physical access attacks against user devices.
- Vulnerabilities in Apple, Google, or other platform-provided code.
- Issues that require already-compromised devices or already-disclosed credentials.
- Theoretical issues without a demonstrable impact path.
Coordinated disclosure
We ask for a reasonable embargo while a fix is developed and shipped. We'll credit you (by name or handle, your choice) in release notes and — for high-impact findings — on this page, unless you prefer to remain anonymous.
Bounties
Abditex does not currently run a paid bug-bounty program. We can offer public credit, swag, and the gratitude of a small team that takes this work seriously. If that ever changes, we'll announce it here.