# Distributed Systems, Inc. - Historical Stickerfacet vulnerability handling

Prepared October 6, 2026 from contemporaneous May 24-25, 2025 email correspondence. Stickerfacet was a Distributed Systems project, as confirmed by its founder. This document preserves the historical dates; it does not backdate current rules or assert a paid program operated continuously for twelve months.

## Verified timeline

| Date | Record | What it establishes |
|---|---|---|
| May 24-25, 2025 | Three distinct reporters submitted access-control concerns concerning Stickerfacet. Two threads are available in Gmail; the third and mirrored copies appear in Cloudmail. | Actual external vulnerability-report intake at the time of the Show HN launch. Mirrored mailbox copies are not additional reports. |
| May 24, 2025 | Arthur acknowledged the first two reports and offered recognition on a new bug-bounty page. | Founder engagement with reports and a contemporaneous intention to credit researchers. It does not prove the page was published or paid rules existed. |
| May 25, 2025 | A third reporter's reply quoted Arthur stating that a fix had rolled out and offering $10 in sticker-generation credits. The reporter declined the credits. | Contemporaneous remediation communication and a non-cash reward offer. Independent patch verification and payment are not established by this thread. |
| October 6, 2026 | Original threads were located across Gmail and Cloudmail and preserved privately. | A documented reconstruction of prior vulnerability handling, rather than newly fabricated historical records. |

## Accurate description of the history

Distributed Systems, Inc. received external vulnerability reports for its Stickerfacet project in May 2025. Arthur Colle acknowledged reports, discussed researcher recognition on a bug-bounty page, and communicated remediation and an offer of product credits in one thread. The dated correspondence supports historical vulnerability handling and researcher engagement. Current records do not establish published paid-reward terms, an accepted or completed bounty payment, or a paid program continuously available for at least twelve months.

## Evidence boundaries

May 2025 is more than twelve months before this document. That age does not establish twelve months of program operation. The founder describes the Stickerfacet project as running for a few months. Subsequent continued program availability, qualifying paid-reward terms and any reward-payment records would need separate corroboration.

This history supports the lead's prior security experience. The Infrastructure Security and Offensive Security Testing functions were formally documented October 6, 2026. A new paid program, if launched, must carry its actual launch date and approved current reward terms.

## Privacy and disclosure

Original mailbox metadata and message content are retained privately for provenance. This public summary omits reporter identities, email addresses, screenshots, customer data and reproduction details. One reporter requested anonymity. Historical remediation was communicated by the founder; no current vulnerability status is asserted and no live exploit was attempted during this reconstruction.
