Reporting a security problem
If you have found a vulnerability in Cirrus Weather, this page tells you
where to send it and what happens next.
Email security@cirrusweather.app
— a person reads it, and you will get a reply.
Cirrus is built by one developer at Legacy 9 Ventures LLC. That means a direct
answer and a fast fix. It also means there is no legal department waiting to
send you a letter.
Safe harbor
If you make a good-faith effort to follow this policy while researching Cirrus,
we will treat your research as authorized, we will work with you to understand
and fix the issue quickly, and we will not pursue or support legal action
against you. If a third party brings action against you for research
conducted under this policy, we will make it known that your work was authorized.
In scope
- The Cirrus Weather iOS, iPadOS and watchOS apps, and their widgets
cirrusweather.app and its subdomains
- The API behind the app, including the Ask Cirrus and Sleep Coach endpoints
- Anything that exposes another person's data, or lets you act as them
Out of scope
- Denial of service, volumetric testing, or anything that degrades the service
for real users. Please don't — tell us the weakness instead of proving it.
- Social engineering, phishing, or physical access attempts against anyone
- Reports from automated scanners with no demonstrated impact
- Missing hardening headers or a TLS configuration grade, absent a real attack
- Vulnerabilities in third-party services we consume — please report those to
the vendor, though we would like to know too
Known, and accepted
Two things get reported often enough to name up front. Neither is a secret,
and neither is news:
- Credentials reachable in the app bundle. Any mobile app that
talks to a third-party API carries a client credential; this is inherent to
the platform, not an oversight. Ours are masked rather than plain, scoped to
what the app actually needs, and rate-limited and capped server-side. If you
find one that is not scoped or capped, that is a real finding and we
want it.
- Getting the assistant to say something odd. Ask Cirrus and the
Sleep Coach are language models with a scope policy. The policy is tested,
but it is probabilistic, not a parser. A reply that is merely off-topic or
unfunny is not a vulnerability. A reply that leaks another user's data, leaks
our configuration, or produces genuinely harmful instructions is — send it
with the exact prompt.
What to include
- What you did, in enough detail that we can do it too
- What you got — a response body, a screenshot, a short recording
- Why it matters: what an attacker gains
- App version and device, if it is a client-side issue
What we commit to
- We acknowledge your report within 3 business days
- We tell you whether we consider it a vulnerability within 10 business days,
and why if not
- We keep you updated while we fix it, and tell you when it ships
- We credit you below unless you would rather stay anonymous
There is no cash bounty. Cirrus is a small independent app and pretending
otherwise would waste your time.
Thanks
People who have reported issues in good faith and helped make Cirrus safer.
No reports yet — this page is new. Yours could be the first.