Unflatten · Legal
Security & Vulnerability Disclosure
Effective 2026-09-19
If you have found a security problem in something we run, we want to hear about it
from you first. Write to security@scry.io with enough detail to reproduce: the host and endpoint, the request, what you
observed, and what you expected. If the report is sensitive, send a short note
without the details first. Our
published OpenPGP key (fingerprint 2F68 CFB1 3EFA AD78 D666 5A80 2C61 DA50 4720 2629) is a sign-only
key that verifies statements from us and cannot receive encrypted mail. This page
is the Policy field of /.well-known/security.txt on every host we serve.
Scope
Everything Unflatten operates: the web hosts (unflatten.com, scry.io, and the sibling product sites served from the same estate), the API at api.scry.io, the MCP door at mcp.scry.io, the console, billing, and the OAuth flow. We are most interested in anything that crosses a boundary: reading or altering another account's data, queries, keys, or balance; executing beyond the read-only SQL surface; escaping a sandbox; bypassing authentication, rate limits, or metering; and leaked credentials. If you find an Unflatten or Scry API key or secret in a public place, send it to us and do not use it.
Out of scope: the third-party sites whose public material we index (report those to their operators); volumetric denial of service; social engineering of our people; physical attacks; reports from automated scanners with no demonstrated impact; and the ordinary cost of a metered service — spending credit on queries is usage, not a vulnerability.
Two surfaces are open on purpose. A chat tree has no owner: its reference is a
long random link, and whoever holds the link can read the tree and add to it, the
way an unlisted document works. The judgement submission board takes entries from
anyone and shows the queue to everyone, under a per-address rate limit. The
endpoint catalog at api.scry.io/v1/scry/context states the access
class of every route; a route that enforces less than its row says is a finding
we want.
Rules of engagement
Test against accounts you own. If you reach data that is not yours, stop at the proof — do not read further, copy, alter, or share it — and tell us. Do not degrade the service for others; the API is shared and metered, so keep your traffic to what a proof requires. Do not spam, phish, or social-engineer. Give us time to fix before you publish: we ask for 90 days from your report.
Safe harbor
Research conducted in good faith under this policy is authorized. We will not pursue civil action or refer it to law enforcement, and we consider it compliant with our Terms of Service. If you are unsure whether something is covered, ask before you test.
What to expect
A person reads every report and replies. Anything beyond that is our call, not a promise.