Security policy
Vulnerability reporting, safe harbor, scope, and coordinated disclosure
Report privately
Email security@oncepad.com. Include the affected URL or version, security impact, reproducible steps or a minimal proof of concept, and how you would like to be credited. Do not include another person's real secrets or publish the issue before we have coordinated a fix and disclosure date.
Safe harbor
Good-faith research conducted under this policy is authorized. We will not pursue or support legal action, including computer-misuse or anti-circumvention claims, when you test only data and systems you own or have permission to test, avoid privacy violations and service degradation, access only what is necessary to demonstrate the issue, and give us reasonable time to remediate.
In scope
- Recovering plaintext, passphrases, or keys through the server, network, storage provider, or a passive observer.
- Reading a secret twice, reading without burning, or revoking without destroying the ciphertext.
- Bypassing the Content Security Policy or Subresource Integrity controls, or causing untrusted JavaScript to execute on a create or reveal page.
- Defeating rate limits, trusted-proxy boundaries, file capability expiry, object isolation, or encrypted-file deletion with demonstrated impact.
- Cryptographic implementation or format flaws, including a mismatch between the shipped client, published format, and test vectors.
Out of scope
Compromised endpoints, a recipient copying a revealed secret, abusive encrypted content, purely volumetric denial of service, social engineering without a product vulnerability, and documented limitations without a bypass are outside the threat model. Abuse and takedown reports belong at the contact on the terms page.
What to expect
We aim to acknowledge reports within 3 business days, provide initial triage within 7, and send regular updates. Coordinated disclosure is normally within 90 days, sooner when a fix ships or exploitation is active. There is no paid bug bounty yet; public credit is available with the reporter's permission.
Incident history
No security incident has been publicly disclosed as of August 18, 2026. Material incidents will be summarized here with impact, dates, remediation, and lessons learned.