Log inJoin the waitlist

Search the help center, features, guides and more.

Trust center

Bug bounty

Rewards for finding security vulnerabilities in Vallkey, what's in scope, and the safe harbor that protects good-faith research.

In scope

  • The apps: iPhone, iPad, Mac, Android, Windows, Linux, the browser extension and the web vault.
  • The server and its API.
  • The cryptographic design and its implementation.

Out of scope

  • Attacks that need a compromised device, or physical access to an unlocked one.
  • Denial of service, spam, and social engineering of our staff.
  • Missing security headers on pages without sensitive content, and reports from automated scanners without a working attack.

Rewards

Every valid report is fixed and credited, and rewards grow with the harm to people’s vaults:

Severity Example
Critical Reading another user’s vault
High Bypassing a legacy contact’s waiting period
Medium Filling a login on the wrong site
Low Revealing metadata the design says is hidden

Safe harbor

If you act in good faith, follow this policy, and give us reasonable time to fix what you find before telling anyone, we won’t take legal action against you, and we’ll ask others not to either.

Report

See responsible disclosure.

Last updated October 5, 2026