In scope
- The apps: iPhone, iPad, Mac, Android, Windows, Linux, the browser extension and the web vault.
- The server and its API.
- The cryptographic design and its implementation.
Out of scope
- Attacks that need a compromised device, or physical access to an unlocked one.
- Denial of service, spam, and social engineering of our staff.
- Missing security headers on pages without sensitive content, and reports from automated scanners without a working attack.
Rewards
Every valid report is fixed and credited, and rewards grow with the harm to people’s vaults:
| Severity | Example |
|---|---|
| Critical | Reading another user’s vault |
| High | Bypassing a legacy contact’s waiting period |
| Medium | Filling a login on the wrong site |
| Low | Revealing metadata the design says is hidden |
Safe harbor
If you act in good faith, follow this policy, and give us reasonable time to fix what you find before telling anyone, we won’t take legal action against you, and we’ll ask others not to either.
Report
Last updated October 5, 2026