Security
How to report a vulnerability, abuse or a copyright problem.
Reporting a vulnerability
Email security@duragit.com. Include what you found, the steps to reproduce it, and what an attacker could do with it. We reply within a few days and keep you updated until it is fixed.
Act in good faith: test only against your own accounts and repositories, do not read or change other people's data, do not degrade the service, and give us reasonable time to fix the problem before you disclose it. We will not pursue good-faith research that follows these rules. There is no paid bug bounty yet.
Other contacts
- Security vulnerabilities: security@duragit.com
- Abuse, spam and illegal content: abuse@duragit.com
- Copyright (DMCA) notices: dmca@duragit.com
How duragit protects your account
- Sign-in is through Google; sensitive actions need a fresh passkey confirmation.
- Access tokens are stored only as hashes, are bound to one organization and always expire.
- Sessions end after 14 days without use and 30 days after sign-in, and you can end them all from your account page.