Vulnerability Disclosure Policy
If you have found a security problem in Keepsake, we want to hear about it, we will not threaten you for telling us, and we will tell you what we did about it.
How do I report a security vulnerability in Keepsake?
Email hello@securekeepsake.com with what you found, how to reproduce it, and what it lets an attacker do. The machine-readable contact is at /.well-known/security.txt. We aim to acknowledge within 3 working days and assess within 10, we will not take legal action against good-faith research under this policy, and we credit reporters on the security page unless they prefer otherwise. There is no bounty programme.
Effective 3 September 2026 · machine-readable contact: /.well-known/security.txt
How to report
Email hello@securekeepsake.com. Put "security" in the subject line so it is not read as a support ticket. A useful report has three things in it: what you found, the shortest reliable way to reproduce it, and what it lets an attacker actually do. A proof-of-concept is welcome; a scanner's PDF, on its own, usually is not.
If you would rather encrypt the report, say so in a first email and we will agree a channel. We do not currently publish a PGP key, because a key we rarely use and might lose is a false promise of confidentiality.
What is in scope
- The vault format and its cryptography — AES-256-GCM, Argon2id key derivation, the wrapped master key, the Family Vault sealed boxes, the Shamir Legacy Kit. This is the part where a flaw matters most, and it needs no permission to test: the vault is a file on your own disk and the format is published byte-for-byte.
- The applications — the Windows desktop app, the Android app and the web app, including the local unlock path, Travel Mode and the duress PIN.
- Licence and release verification — the Ed25519 signature checks. A way to forge a licence is a commercial problem; a way to forge a release is a code-execution problem on every installed copy, and we would treat it accordingly.
- securekeepsake.com and app.securekeepsake.com — the portal, the account area, the admin API, Secure Send.
What is out of scope
- Denial of service, traffic floods, and automated scanning heavy enough to degrade the site for other people.
- Social engineering of the owner, of our hosting provider, or of customers.
- Accessing, modifying or exfiltrating anybody else's data. If you can demonstrate that you could, stop there and describe it — we will believe you.
- Reports whose whole content is a missing header, a TLS configuration grade, or a version banner, with no path to impact. We will read them; we will not usually act on them.
- Findings in third-party services we do not control (the host, Cloudflare, the storage provider you chose for sync). Tell them, and tell us if it affects Keepsake users.
What we commit to
- Acknowledgement within 3 working days, and an assessment — severity, whether we agree, and a rough fix date — within 10.
- Safe harbour. We will not pursue or support legal action against anyone who researches in good faith under this policy, and we will say so publicly if somebody else tries.
- Credit, if you want it. Named on the security page, with a free lifetime licence. Anonymity on request, equally.
- We will tell you when it is fixed, and what the fix was, before we publish anything.
- 90 days. Publish after 90 days whether or not we have shipped a fix. If we need longer we will ask and give a reason; the decision stays yours.
What we do not offer
There is no bounty programme. Keepsake is one person selling £19 licences, and advertising a payout we could not reliably fund would be the same species of claim as an unaudited zero-knowledge promise. If that changes, this paragraph changes with it.
There is also, as of today, no external security audit of the cryptography. What exists is an automated cryptographic and licence test suite, a published vault format anyone can implement against, a signed release channel, and a documented design on the security page. That is evidence you can check yourself; it is not the same as evidence a third party has checked, and we say so on the criteria page as well as here. Commissioning one is planned rather than dismissed.
Questions
How fast will you respond?
We aim to acknowledge a report within 3 working days and to give you an assessment within 10. Keepsake is a small operation, so if you have heard nothing after 5 working days, send the email again rather than assuming it was ignored — it usually means it went to spam.
Do you pay a bounty?
Not at present. We are a one-person company selling £19 licences, and a bounty programme we could not honour would be worse than saying so plainly. What we do offer is credit on the security page for anyone who wants it, a free lifetime licence, and a straight answer about what we fixed and when.
Can I test against the live site?
Yes, within limits: no denial of service, no automated scanning that degrades service for others, no social engineering of the owner or the host, and no accessing another person's account or data. If a proof needs one of those, describe it instead of doing it and we will work out how to demonstrate it safely.
What about the vault format and the apps?
Those are the interesting targets and testing them needs no permission at all — the vault is a local file on your own machine, the format is published, and the desktop, Android and web clients are yours to pull apart. Findings in the cryptography, the key wrapping, the licence verification or the release signing are the most valuable reports we can receive.
Will you take legal action against me?
Not for research conducted under this policy in good faith. We will not pursue or support a claim against anyone who follows it, and if a third party does, we will say publicly that the work was authorised.