Bug Bounty Guide is designed as a local, offline-first application for security researchers. Protecting your data and providing transparency is a priority.
The application uses a local SQLite database (app_data/bug_bounty_guide.db) for all storage. To protect sensitive information, field-level encryption is implemented using the cryptography library (Fernet symmetric encryption). The encryption key is securely generated and stored in your operating system's native keyring via the keyring library, tying it to your local OS user account.
- Encrypted Fields: Highly sensitive fields, specifically Note content and Finding reproduction steps, are encrypted at rest.
- Scheme: Encrypted fields are stored as base64 strings prefixed with
ENC:. - Algorithm: Fernet symmetric encryption (AES-128-CBC with SHA256 HMAC).
- The encryption key is permanently bound to your current OS user account.
- No Key Export/Import: There is currently no UI or mechanism to export or import the encryption key.
- Portability: If you copy the raw
bug_bounty_guide.dbfile to another machine or a different user account on the same machine, the encrypted fields will be unreadable because the new environment lacks the keyring key. Always use the built-in Export/Backup functionality to migrate projects. - No Full-Disk Encryption: The database itself is not fully encrypted; project metadata, finding titles, etc. remain in plaintext. We recommend relying on full-disk encryption (FileVault, BitLocker, LUKS) for complete protection.
When exporting projects, the application generates a portable .zip archive containing your data as JSON and your attachments.
- Integrity: Each archive includes an
attachments_manifest.jsonand internal SHA-256 manifest verification to ensure data consistency. - Safety: The application performs automatic pre-delete backups.
- Migrations: Schema version tracking ensures compatibility when importing backups across different versions of the application.
We take supply chain security seriously for an application aimed at security researchers:
- Checksums: SHA-256 checksums (
CHECKSUMS.sha256) are provided for all release artifacts. - SBOM: A CycloneDX Software Bill of Materials (
sbom.cdx.json) is included with every release for dependency transparency.
Currently in public beta, the release process utilizes automated, reproducible builds via GitHub Actions CI. Code signing (macOS notarization and Windows Authenticode) is planned for the stable release to guarantee authenticity.
- No Telemetry: We do not track your usage, clicks, or behavior.
- No Cloud Sync: Your data never leaves your machine unless you explicitly export it.
- No Network Calls: The application operates entirely offline (except for future optional update checking).
- No Sensitive Content in Logs: Application logs (
app_data/app.log) are sanitized and do not contain database contents, project evidence, or encryption keys.
If you discover a security vulnerability in Bug Bounty Guide, please practice responsible disclosure.
- Contact: Email us at security@bugbountyguide.example.com
- Response: We aim to acknowledge receipt within 48 hours and provide a timeline for remediation based on the severity of the issue.