Security

Updated September 8, 2026 · covers crinkle.dev and the Crinkle beta app

Found something? Email support@crinkle.dev with "SECURITY" in the subject. We will acknowledge within 5 working days. Please give us a chance to fix it before you publish, and we will not pursue you for good-faith research that follows this page.

Reporting a vulnerability

Send the report to support@crinkle.dev. The machine-readable version of this page is at /.well-known/security.txt. A useful report usually has:

We are a small team and this is beta software, so we would rather hear about something uncertain than not hear about it. If you are not sure whether a behavior is a bug or a design decision, ask.

What we ask

We have no paid bounty programme. What we can offer is a fast answer, credit if you want it, and a fix.

Where the interesting boundaries are

Crinkle is an autonomous coding agent, so it deliberately does things most apps do not: it writes files, runs developer commands, and drives a browser. Reports that land in these areas are the most valuable:

Out of scope: the security of code the AI generates for your project (review it before shipping, as the terms say), issues in third-party AI providers or sites you connect, and reports that require an attacker who already has full control of your user account on your machine.

How the app protects what you give it

Crinkle is beta software and has not had an independent security audit. We would rather say that plainly than imply otherwise.

Downloading Crinkle safely

Only two places are ours: the Microsoft Store listing, and the download links on crinkle.dev (which point at our GitHub releases). If you find Crinkle installers anywhere else, they are not from us — please tell us.

Contact

Security reports: support@crinkle.dev, subject line "SECURITY". Everything else: the same address, without the shouting.