Security

Last updated: September 27, 2026

1. Our commitment

Sysvia syncs files, shares a clipboard, and shares a keyboard and mouse between your own devices, so we take reports of security issues seriously and will work with anyone who reports one in good faith. This page explains what's in scope, how to report something, and what you can expect from us.

2. In scope

  • The Sysvia desktop application, for any supported operating system.
  • The local-network protocol used to sync files, clipboard, and input between your devices.
  • The Sysvia website, including sign-in, account, and licensing.

3. Out of scope

  • Denial-of-service, spam, or volumetric testing against our website or infrastructure.
  • Social engineering of our team, contractors, or users.
  • Physical access to a device or network you don't have permission to test.
  • Issues in third-party services we rely on (for example our hosting, payment, or authentication providers) — please report those directly to the provider.
  • Automated scanner output with no demonstrated, specific impact.

4. How to report an issue

Email us through our contact page with a description of the issue, the steps to reproduce it, the affected version and operating system, and its potential impact. Please don't include real user data in a report — a reproduction using your own test data is enough.

5. What happens next

We aim to acknowledge reports within 3 business days. We'll investigate, keep you updated on progress, and let you know once a fix has shipped. How long a fix takes depends on its severity and complexity — we'll be upfront with you about timing as we learn more.

6. Safe harbor

We won't pursue legal action against anyone who reports a vulnerability in good faith and in line with this policy: testing only against your own devices or accounts, avoiding privacy violations and disruption to others, not accessing or modifying data beyond what's needed to demonstrate an issue, and giving us a reasonable chance to fix it before sharing it publicly.

7. Recognition

We don't currently run a paid bug bounty program. With your permission, we're glad to credit you by name in our release notes for a valid report that leads to a fix.

8. Contact us

Report a security issue, or ask a question about this policy, through our contact page.