# CrabiX security contact

> Use support@crabix.ai to report security issues affecting the CrabiX website, release delivery, or desktop app. The machine-readable security contact file is published at /.well-known/security.txt.

Canonical: https://crabix.ai/security
Markdown: https://crabix.ai/security.md
Author: CrabiX
Published: 2026-06-13
Last updated: 2026-06-30
Category: Security

## Key takeaways

- Machine-readable security metadata: /.well-known/security.txt.
- Security contact: support@crabix.ai
- Do not perform destructive testing, data exfiltration, or denial-of-service testing without written permission.
- Local-first product security details live in the security-local-first guide.

## How should security issues be reported?

Email support@crabix.ai with a concise description, affected component, reproduction steps, impact, and any relevant logs or screenshots.

Machine-readable file: [/.well-known/security.txt](/.well-known/security.txt).

Canonical policy page: [/security](/security).

Please avoid public disclosure until the CrabiX team has had a reasonable opportunity to investigate and fix a valid issue.

## What is in scope?

In scope: crabix.ai, releases.crabix.ai release delivery, public download metadata, and security issues in the CrabiX desktop app or local gateway that can be responsibly reproduced.

Out of scope without written permission: denial-of-service testing, social engineering, phishing, spam, physical attacks, and attempts to access data that is not yours.

The local-first security model is explained in the [security and privacy guide](/security-local-first).

Reports should avoid including real user secrets or third-party personal data.

## FAQ

### Where is CrabiX security.txt?

CrabiX publishes security.txt at /.well-known/security.txt and redirects /security.txt there.

### Does this policy authorize security testing?

No. The policy provides contact and scope guidance; it does not grant permission for destructive testing, denial of service, exfiltration, or testing against third-party systems.

## Model digest

CrabiX security contact metadata is published at https://crabix.ai/.well-known/security.txt with policy page https://crabix.ai/security. Security reports should go to support@crabix.ai and include affected component, reproduction steps, and impact. The policy covers crabix.ai, releases.crabix.ai release delivery, public download metadata, and responsibly reproducible CrabiX app issues. It does not authorize destructive testing or data exfiltration.

## Related CrabiX guides

- [/security-local-first](https://crabix.ai/security-local-first)
- [/download](https://crabix.ai/download)
- [/releases](https://crabix.ai/releases)
- [/privacy](https://crabix.ai/privacy)
- [/terms](https://crabix.ai/terms)
