Deputy Shell Security Policy
This page is the public security and vulnerability-reporting policy for Deputy Shell.
This policy covers the official Deputy Shell Android application and Deputy Shell-operated services at deputyshell.com, including the closed-alpha signup and tester communication system.
Security reports about these services are welcome. This does not grant permission to actively test production website, signup, email, database, administration or Cloudflare infrastructure beyond ordinary intended use.
Contact routing
Please use the right address for the type of request:
| Topic | Contact |
|---|---|
| Suspected Deputy Shell vulnerability or coordinated disclosure | security@deputyshell.com |
| Ordinary bugs, app support, diagnostics and tester access problems | support@deputyshell.com |
| Privacy questions, data-rights requests and closed-alpha data requests | privacy@deputyshell.com |
| Development, integration and internal administration enquiries | devteam@deputyshell.com |
Do not send vulnerability reports to personal accounts, public forums or unrelated project channels.
What to include in a vulnerability report
Helpful reports include:
- Deputy Shell version;
- Android version;
- device model;
- affected feature;
- clear reproduction steps;
- expected result;
- observed result;
- potential impact; and
- sanitised screenshots or logs where useful.
Please keep reports focused on Deputy Shell behavior and include only the information needed to understand and reproduce the issue.
What not to send by email
Do not email:
- passwords;
- API keys;
- access tokens;
- refresh tokens;
- authentication files;
- private keys;
- confidential source code;
- full private repositories;
- complete workspace archives;
- unredacted credentials;
- raw secret-bearing diagnostic material.
If sensitive material is needed to investigate a report, send an initial description first and wait for safer handling instructions.
Response expectations
Deputy Shell is currently operated by one independent developer.
Security reports will be reviewed as capacity allows. Credible urgent issues will be prioritised. Additional information may be requested when a report is incomplete or cannot be reproduced.
Please use coordinated private disclosure and avoid publishing technical details before there has been reasonable private coordination.
Deputy Shell does not currently operate a paid bug-bounty programme. Reporting a vulnerability does not guarantee payment, public credit, acceptance of the report, a fixed acknowledgement deadline, a fixed remediation deadline or compatibility with every device or environment.
Permitted testing
Security testing is permitted only within this scope:
- your own device;
- your own Deputy Shell installation;
- your own accounts;
- your own files and workspaces; and
- an official current Deputy Shell closed-alpha build.
Website or backend security issues discovered during ordinary intended use of deputyshell.com or the closed-alpha signup flow may be reported. Production website, signup, email, database, administration and Cloudflare infrastructure are not authorised penetration-testing targets.
Keep testing proportionate and stop immediately if testing reaches any system outside this scope.
Prohibited testing
This policy does not authorize active security testing of Deputy Shell's production website, closed-alpha signup system, email services, database, administration systems or Cloudflare configuration beyond ordinary intended use.
Do not:
- attempt to bypass authentication or Cloudflare Access protecting the tester dashboard;
- perform denial-of-service, resource-exhaustion or other disruptive testing;
- use malware, social engineering or credential-stealing techniques;
- test OpenAI, Google, GitHub, Cloudflare, Firebase, Resend, package registries or any other third-party service under this policy;
- copy, retain, alter or disclose personal, confidential or credential information encountered accidentally; or
- publicly disclose a reported vulnerability before reasonable private coordination.
Testing inside Deputy Shell must remain limited to your own device, your own installation, your own accounts and your own files.
If ordinary use unexpectedly exposes information that does not belong to you, stop, do not copy or retain it, and report what happened privately to security@deputyshell.com.
Deputy Shell security boundary
Deputy Shell is a general-purpose terminal and development workspace.
Commands, scripts, dependencies and agents authorised by the user may read, modify, delete or transmit accessible data. Projects and sessions are organizational boundaries inside Deputy Shell. They are not separate Android security sandboxes.
Code executed inside Deputy Shell may operate within Deputy Shell's app-private process and storage boundary. Malicious code deliberately executed by the user may access credentials or files available within that boundary.
Deputy Shell uses Android app-private storage, disabled Android backup for app-private data, restricted diagnostics, workspace export exclusions, optional telemetry controls and runtime-integrity verification to reduce accidental disclosure and persistent runtime tampering.
Runtime-integrity verification protects shipped immutable runtime files from persistent modification and triggers verified reprovisioning when protected files are missing, modified, symlinked, the wrong type or otherwise unexpected. Runtime-integrity verification does not make arbitrary commands, dependencies, packages or agent actions safe.
Rooted devices, modified operating systems, debugging environments and repackaged builds may weaken platform and application protections.
Third-party services, including OpenAI, Google, GitHub, Cloudflare, Firebase, Resend and package registries, have their own security, abuse-handling and account-recovery processes. Issues in those systems should also be reported through the relevant provider's official channels.
More help
For ordinary bugs, app support or tester access problems, visit Support.
Deputy Shell
Join Closed Alpha