CROWBOT

Initial Release · security

Security and responsible disclosure

CrowBot welcomes good-faith reports that help protect people, passkey accounts, purchases, brains, provider credentials, and the service.

Effective 29 August 2026 · CrowBot is operated by an Australian individual.

Private security-reporting ticket

Choose “Security, abuse, or safety report” on the Support page. The plain-text form returns a ticket ID and private access token instead of collecting an email address. A created ticket confirms receipt by the system; it does not create a response deadline, safe-harbour agreement, confidentiality promise, bug bounty, or payment promise.

Current security design

Browser and network

  • HTTPS in hosted environments and restrictive browser security headers;
  • same-origin checks, with account mutations restricted to the exact configured account origin;
  • action-specific Cloudflare Turnstile verification before account creation/sign-in/recovery, new support tickets, Checkout, or new owner login;
  • server-side Turnstile validation requires a fresh single-use token with the exact CrowBot hostname and action before protected work begins;
  • bounded request bodies and strict content handling;
  • no framing and no arbitrary form destinations.

Secrets and local data

  • Crow-funded provider secrets remain on the Worker and are not sent to the browser;
  • user-verified passkeys keep their private key in the authenticator; CrowBot stores public credentials and hashed sessions only;
  • your provider keys use session storage by default and persist only after an explicit remember choice;
  • brain export/sync excludes provider credentials, recovery codes, raw media, photos, and pairing secrets;
  • account and licence recovery codes are stored only as keyed/one-way hashes.

Access and payments

  • server-authoritative trial, licence, Premium Voice, refund, and dispute decisions;
  • test/live Stripe environment separation and signed webhook verification;
  • signed account/licence/namespace/origin/environment/device-bound offline authorization;
  • rate limits, bounded retention, allowlists, and fail-closed checkout/fulfilment checks.

Model request boundaries

  • Crow-funded model requests are limited to the exact configured free-model allowlist;
  • untrusted browser-supplied system or developer roles are downgraded before forwarding through the Crow-funded route;
  • request sizes, content types, remote media, quotas, and upstream responses are validated and bounded.

These controls reduce risk; they do not make CrowBot, a browser, a provider, or an internet connection perfectly secure.

Turnstile is an abuse-control signal, not authentication, proof of identity, a Stripe entitlement, or a replacement for rate limits, owner credentials, checkout validation, and signed Stripe webhooks. The verification token is not written to CrowBot’s browser storage, readable brain, D1 records, URLs, or application logs.

Protect your CrowBot

What a useful report should contain

Provide the smallest evidence needed to reproduce and fix the issue:

Do not include live secrets, private prompts, complete brain exports, unnecessary personal information, payment-card data, or another person’s data. If a secret appears in evidence, rotate it before sharing a redacted copy.

Good-faith testing boundaries

No bug bounty, reward, payment, employment, or reimbursement is currently offered or implied. This page does not authorize unlawful activity or create a contract.

Scope and third parties

Reports about CrowBot’s website, passkey accounts and sync, Worker APIs, licence/offline entitlement, payment fulfilment, and shipped client code are in scope. Vulnerabilities solely in Stripe, Cloudflare, OpenRouter, Groq, Fish Audio, a browser, operating system, or another provider belong under that provider’s policy. Do not test a third-party system merely because CrowBot calls it.

Security tickets and messages are retained for 2 years after the ticket’s last activity, then removed by bounded cleanup. Do not submit information that is not needed for the report.

Privacy handling is described in the Privacy notice. Purchase and consumer-rights terms are on the Access and purchase terms page.