Reporting a security problem

How to report

Email [email protected]. Please describe what you found, the exact steps to reproduce it, and what an attacker could do with it. A short proof is worth more than a scanner report.

We would rather hear about something small than not hear about it. If you are unsure whether it counts, send it.

What we ask of you

Do not run automated scanners or load tests against the live service; ask us first and we will point you somewhere safe. Do not access, change or keep anybody else's documents or account - if you can reach another person's data, stop there and tell us what you did to get that far.

Give us a reasonable chance to fix the problem before you publish. We will tell you when it is fixed, and we are happy for you to write about it afterwards.

What we do not have

This service holds no security certification. There is no ISO 27001 certificate, no SOC 2 report and no external audit behind it, and any site that displays such a badge without one is misleading you. We would rather say so than let the omission imply otherwise.

What there is instead is written down and checkable: the security model in the project's SECURITY.md, uploads scanned before any engine opens them, documents deleted on a fixed schedule, and a test suite that fails the build when a stated protection stops being true.