Security at Olympus Console
Olympus Console is developed by Fortune Five. Security is layered into the design rather than added on: minimising data, pinning trust to the user's own certificates, and keeping the relay a dumb pipe.
Our security posture
The backend you run is open source at github.com/olympus-console/olympus-console, so each of the claims above is auditable, not just asserted.
Responsible disclosure
If you have found a vulnerability in Olympus Console — the app, the relay, the backend, or the surrounding infrastructure — please report it to us. We will coordinate a fix with you before any public disclosure.
Email: security@olympus-console.app. A copy of this disclosure policy is also published at /.well-known/security.txt so scanners can locate it automatically.
PGP fingerprint: ...FINGERPRINT TO BE PUBLISHED.... A signed key will be published at this address; until then, please send your report as plain text.
No DMCA / no legal action. We will not pursue DMCA, takedown, or legal action against researchers acting in good faith, staying within this policy, and giving us a reasonable window to remediate before any public disclosure.
In scope
- The Olympus Console backend you run on your own machines.
- The Olympus Console push relay we operate.
- The Olympus Console app on iPhone and Mac.
- Availability and correctness of /.well-known/security.txt.
Out of scope
- Rate-limit or volumetric denial-of-service testing.
- Social-engineering of Fortune Five staff or users.
- Vulnerabilities in third-party vendor systems (Apple, Soniox, GitHub, etc.).
- Self-XSS, clickjacking on unauthenticated marketing pages, or other low-impact UI issues.
Response targets
- Acknowledgement: within two business days of receiving your report.
- Status updates: at least every seven calendar days until the issue is resolved or a fix is shipped.
- Credit: with your permission, we will list you in an acknowledgements section once the issue is fixed.