Security
Report a vulnerability
If you find a security problem in this website or its dashboard, please tell us before you tell anyone else.
How to report
Email support@firekeeper.sh. Plain text is fine. Please include:
- what you found and where;
- the steps to reproduce it;
- what an attacker could do with it.
Give us a reasonable time to fix the problem before you share it. Our contact details are also in /.well-known/security.txt.
Scope
In scope:
- this website, firekeeper.sh;
- the dashboard on it: accounts, passkeys, recovery codes, sessions and licenses;
- the license format and the signing behind it;
- the install script served at
/install.
Firekeeper itself is not released, so there is no product to test yet. Denial of service, spam, social engineering and physical attacks are out of scope.
Testing in good faith
- Use only accounts you created. Do not access, change or delete other people's data.
- Stop as soon as you have shown the problem, and tell us what you accessed.
- Do not degrade the site for others. Keep automated testing slow and light.
How this site protects you
- No trackers
- No analytics scripts, no tag managers, no ads, no embeds. Fonts are served from this site. Every page makes requests only to firekeeper.sh, and a strict Content Security Policy enforces that in your browser. Nothing on this site asks your browser to report to anyone else. For counting, we count requests by page type, by kind of client and by result. For counting, we never store your address, your browser's name, the page address you asked for, your country or where you came from. The privacy page says exactly what is counted.
- Passkeys only
- You sign in with a passkey. There are no passwords to steal or reuse, and no third-party sign-in. Recovery codes are stored only as hashes and each works once.
- Signed licenses
- Every license is signed with Ed25519. You can check one yourself on the verify page, in your browser, against our published public keys.
- Sessions
-
The session cookie is
HttpOnly,SecureandSameSite=Lax. We store only a hash of it. Changes to your account need a request from this site's own origin. Adding or removing a passkey and making new recovery codes need a passkey check from the last five minutes. Removing a passkey or making new codes signs out every other session. Deleting the account needs a passkey check made for that deletion.