1. Our approach
We treat any way that Brello 1.0 or this website could expose your questions, photos, answers or chats, or take an action you didn’t ask for, as a vulnerability, and we want to hear about it.
Brello 1.0 has no Brello server, no account system and no analytics, and it processes your questions, photos and answers on the phone. That narrows what an attacker can reach, but it doesn’t remove the risk: an app can still store data where other apps can read it, make a network request it shouldn’t, or be misled by content it reads from the web. Under commitment 01 of the Brello Charter, any request Brello 1.0 makes beyond those our privacy policy lists is a security issue.
2. How to report a vulnerability
Email [email protected]Address to be confirmed with ‘Security report’ in the subject line. The link opens your email app. Please include:
- a description of the issue and its potential impact;
- the steps to reproduce it, including the app version (shown at the foot of Brello’s Settings as ‘Brello 1.0 · Prototype’), your phone model and its Android version;
- any proof-of-concept code, screenshots or recordings;
- how you’d like to be credited, if at all.
We’ll confirm we’ve received your report, keep you updated as we investigate, and tell you when it’s fixed.
Safety issues that are not vulnerabilities, such as a harmful answer or a safeguard that doesn’t work as our safety page describes, are welcome too. Send them to the same address with ‘Safety report’ in the subject line.
3. Scope
Brello 1.0 and this website are in scope, including how they use third-party components; the third parties’ own systems are not.
In scope
- The Brello 1.0 Android app, version 1.0.0.
- This website and its hosting configuration.
- Any network request Brello 1.0 makes beyond those listed in section 5 of our privacy policy.
- Brello data readable by other apps, or included in Android backups or device-to-device transfer.
- Web content or prompt injection that makes Brello reveal chat content or make a request you didn’t ask for.
- How Brello downloads, stores and loads model files.
Out of scope
- Vulnerabilities in third-party services and components themselves, such as search engines, websites, Hugging Face, Android System WebView, LiteRT-LM or the open models. Please report them to their owners.
- Denial-of-service and volumetric testing.
- Social engineering of our team, and physical attacks.
- Issues that need a rooted or already-compromised device, unless they show a design flaw.
- Wrong answers with no security impact. Please send them as safety reports (section 2).
- Documented properties of the prototype, such as its installation from an APK outside Google Play and its debug signing.
Brello Super Intelligence is in development and isn’t available, so it isn’t in scope yet. We are designing it so that independent researchers can verify what runs, where it runs and what it keeps, and we will publish what they need before anyone outside the team uses its sealed compute (Brello Charter v1.0, commitment 08). ‘Private compute you can verify’ describes that work.
4. Safe harbour
If you act in good faith and follow this policy, we won’t pursue or support legal action against you for your research, and we’ll consider it authorised. Good faith means you:
- test only against your own devices, data and accounts;
- don’t access, modify or keep anyone else’s data;
- avoid degrading the service for others;
- give us reasonable time to fix the issue before you disclose it publicly, normally 90 days, and longer only if we agree it’s necessary;
- don’t demand payment in exchange for not disclosing.
We can authorise research only on systems we control. This policy can’t authorise testing of search engines, websites, Hugging Face or other third parties.
5. Recognition
With your permission, we’ll credit you when we publish a fix. Before anyone outside the team uses Brello Super Intelligence, we will publish its architecture (Brello Charter v1.0, section 4), and we intend to invite targeted review of the parts that protect your data.
6. Questions
If you aren’t sure whether something is in scope, email us before you start, with ‘Security question’ in the subject line. Questions about personal data are covered by our privacy policy, and our company page lists our other contacts.
7. Changes to this policy
If we change this policy, we’ll update the date at the top and record the change below, with the date it took effect. Earlier versions will be listed here with their dates and kept available.
- This version. Covers Brello 1.0 (version 1.0.0) and this website.