RESPONSIBLE DISCLOSURE · ONE BUILDER, ONE INBOX · LAST UPDATED SEPTEMBER 24, 2026
PHNTM One is sold on a privacy promise, so a security flaw is the most important kind of bug there is. If you find one in the device or in this website, please report it privately so it can be fixed before anyone else is exposed to it.
How to report
Email [email protected] with "Security report" in the subject. Please include what you found, the steps to reproduce it, and what an attacker could do with it. If it helps, include the device version shown by phntm status.
The machine-readable version of this page lives at /.well-known/security.txt.
What's in scope
- The PHNTM One device: its software, its local web and phone interfaces, update and recovery paths, and anything that could make data leave the box without the owner choosing it.
- This website, www.phntmcore.com, including checkout and the community pages.
Out of scope: third-party services we use (Stripe, Cloudflare, Formspree, Google Ads). Please report those to their owners. Denial-of-service and social-engineering tests are also out of scope.
What happens next
- You get a reply from the person who built the device, usually within a few days.
- I'll confirm the issue, keep you posted while it's fixed, and tell you when the fix ships.
- With your permission, I'll credit you in the build log once owners have the fix.
Please don't
- Access or change anyone else's data, or test on a unit you don't own.
- Publish the details before a fix is available.
There is no paid bug bounty. This is a one-person company, and I'd rather promise less and keep every promise.