Security policy

Vulnerability reporting, safe harbor, scope, and coordinated disclosure

Report privately

Email security@oncepad.com. Include the affected URL or version, security impact, reproducible steps or a minimal proof of concept, and how you would like to be credited. Do not include another person's real secrets or publish the issue before we have coordinated a fix and disclosure date.

Safe harbor

Good-faith research conducted under this policy is authorized. We will not pursue or support legal action, including computer-misuse or anti-circumvention claims, when you test only data and systems you own or have permission to test, avoid privacy violations and service degradation, access only what is necessary to demonstrate the issue, and give us reasonable time to remediate.

In scope

  • Recovering plaintext, passphrases, or keys through the server, network, storage provider, or a passive observer.
  • Reading a secret twice, reading without burning, or revoking without destroying the ciphertext.
  • Bypassing the Content Security Policy or Subresource Integrity controls, or causing untrusted JavaScript to execute on a create or reveal page.
  • Defeating rate limits, trusted-proxy boundaries, file capability expiry, object isolation, or encrypted-file deletion with demonstrated impact.
  • Cryptographic implementation or format flaws, including a mismatch between the shipped client, published format, and test vectors.

Out of scope

Compromised endpoints, a recipient copying a revealed secret, abusive encrypted content, purely volumetric denial of service, social engineering without a product vulnerability, and documented limitations without a bypass are outside the threat model. Abuse and takedown reports belong at the contact on the terms page.

What to expect

We aim to acknowledge reports within 3 business days, provide initial triage within 7, and send regular updates. Coordinated disclosure is normally within 90 days, sooner when a fix ships or exploitation is active. There is no paid bug bounty yet; public credit is available with the reporter's permission.

Incident history

No security incident has been publicly disclosed as of August 18, 2026. Material incidents will be summarized here with impact, dates, remediation, and lessons learned.