Security policy

How to report a vulnerability in Hotshot Orchestrator.

Supported versions

Only the latest release of Hotshot Orchestrator (the version on the download page, which installed apps update to by themselves) receives security fixes. The hosted Hotshot Sync service is always the current version. The self-hosted relay is supported at the version in the latest release's tag.

Reporting

E-mail security@hotshotinteractive.com with:

  • what is affected (component and version),
  • how to reproduce it, and what an attacker gains,
  • whether you would like to be credited.

Please do not open a public issue or pull request for a vulnerability. We will acknowledge your report and give a first assessment within 7 days, keep you informed while we fix it, and agree a disclosure date with you (normally when the fix has shipped, at most 90 days after the report). There is no bug bounty yet; we will credit you in the release notes if you wish.

In scope
  • the desktop and Android app, including the hub, the gateway, the dev API, the updater and Hotshot Sync on the device;
  • the bundled sidecars (the computer-use and OCR programs);
  • the Sync servers: the hosted service and the self-hosted relay, and the Sync protocol;
  • the workspace package registry, the index signing and its verification in the app.
Out of scope

The AI agent programs the app runs (report those to their makers, such as Anthropic, OpenAI or Google), third-party MCP servers, findings that need an already compromised device or administrator access, social engineering, denial of service by volume, and reports from automated scanners without a demonstrated impact.

Safe harbour

We will not take legal action against, or ask law enforcement to investigate, anyone who researches and reports a vulnerability in good faith under this policy: who avoids harming users and their data, tests only against their own accounts and devices, does not degrade the hosted service, and gives us reasonable time to fix the issue before disclosing it.