Vulnerability Disclosure Policy

Last updated: 2026-06-04

We want Boswell to be safe to use. If you've found a security vulnerability in Boswell, we'd genuinely like to hear about it. This policy explains what's in scope, how to report a problem, and what you can expect from us in return.

Reporting a vulnerability

Email security@meetboswell.com with:

Please report in English where you can. If you need to share sensitive details, say so and we'll arrange a secure channel.

What to expect: we aim to acknowledge your report within 5 business days, keep you updated as we investigate, and let you know when the issue is resolved. We'll credit you for the discovery if you'd like to be named and the report leads to a fix — just tell us how you'd like to be acknowledged.

Good-faith guidelines

We consider security research conducted under this policy to be authorized, provided you:

Safe harbor

If you make a good-faith effort to follow this policy while researching and reporting a vulnerability, we will not pursue or support legal action against you for that research, and we'll treat your activity as authorized under the laws that govern unauthorized access to computer systems. If a third party brings a claim against you for activity that was conducted in line with this policy, we'll make it known that your actions were authorized.

This safe harbor covers only the systems we operate and control (see "In scope"). It cannot waive the rights of third parties, and it does not authorize you to break laws or to act against systems we don't own. If you're ever unsure whether something is permitted, ask us first at security@meetboswell.com — we're happy to clarify before you test.

In scope

Out of scope

The following are operated by third parties, not by Boswell, and are not covered by this policy. Please report issues in them directly to the vendor, not to us:

Also out of scope, and not something we'll usually act on: reports that are purely theoretical with no demonstrated impact, missing security headers without a concrete exploit, best-practice or "hardening" suggestions with no vulnerability behind them, and findings that require physical access to a victim's unlocked Mac, social engineering, or a compromised device.

A note on Boswell's design

Boswell is local-first: your recordings and transcripts stay on your Mac and are never uploaded to a Boswell server. The only data we hold server-side is the record that supports your subscription (see our Privacy Policy). That shapes what's interesting from a security standpoint — the highest-value targets are the sign-in and entitlement flow, the subscription backend, and anything that could cause the app to leak local data off the device.

Contact

Security reports: security@meetboswell.com. For non-security questions, use support@meetboswell.com instead.