Coordinated vulnerability disclosure
Last reviewed July 2026 · v1.0
Semparo holds the most sensitive things a person can write down, and we want to hear about security problems before anyone gets hurt by them. If you have found a vulnerability in our service or in the cryptographic scheme behind it, this page tells you how to report it and exactly what we will do in return.
We would rather learn about a flaw from you than from an incident. Good-faith research is welcome here.
How to report
Email contacts@semparo.com with what you found. Include enough for us to reproduce it: the affected page or endpoint, the steps, and the impact as you see it. If a proof of concept helps, attach it. One report per issue is easier for both of us to track.
Do not include real personal data or anyone else's account contents in a report. If a flaw exposes data that is not yours, describe it rather than collecting it.
What we promise
This is what we deliver on every report, and nothing beyond it, so you know where you stand:
- We acknowledge your report within 3 days. A human replies to confirm we received it and that we are looking.
- We work it on a coordinated timeline. We aim to fix confirmed issues and disclose them together with you, on a default timeline of about 90 days from your report. If a fix needs longer, or you need it public sooner, we agree the date with you rather than letting it drift. We will not sit on a report in silence.
- We credit you. With your consent, we name you in a public recognition list after the fix ships. Recognition is the reward we offer.
- We do not pay cash bounties. We say this plainly so there is no misunderstanding: there is no monetary reward, only recognition and our thanks.
Safe harbor
If you make a good-faith effort to follow this policy, we will treat your research as authorized. We will not pursue or support legal action against you for it, and we will not ask others to.
Good faith means: you access only what you need to demonstrate the issue, you do not degrade the service for others, you do not access, modify, or keep data that is not yours, and you give us a reasonable chance to fix the problem before you make it public. Test against your own accounts and your own data.
In scope
- The Semparo web application and its API.
- The cryptographic scheme described in our published paper and on our security architecture page.
Findings that are more useful to us than a generic scanner: anything that touches the two invariants we treat as sacred, which are no false release of a vault, and the zero-knowledge boundary that keeps us from reading your content. Authorization flaws, replay, and account-takeover paths rank high.
Out of scope
- Reports from automated scanners with no demonstrated impact.
- Social engineering of our staff, users, KeyKeepers, or recipients.
- Denial of service, volumetric or otherwise.
- Findings that require a compromised device or a person already having your credentials.
None of this stops you from reporting something you think matters. If in doubt, send it. We would rather triage a borderline report than miss a real one.