Coordinated vulnerability disclosure

Last reviewed July 2026 · v1.0

Semparo holds the most sensitive things a person can write down, and we want to hear about security problems before anyone gets hurt by them. If you have found a vulnerability in our service or in the cryptographic scheme behind it, this page tells you how to report it and exactly what we will do in return.

We would rather learn about a flaw from you than from an incident. Good-faith research is welcome here.

How to report

Email contacts@semparo.com with what you found. Include enough for us to reproduce it: the affected page or endpoint, the steps, and the impact as you see it. If a proof of concept helps, attach it. One report per issue is easier for both of us to track.

Do not include real personal data or anyone else's account contents in a report. If a flaw exposes data that is not yours, describe it rather than collecting it.

What we promise

This is what we deliver on every report, and nothing beyond it, so you know where you stand:

Safe harbor

If you make a good-faith effort to follow this policy, we will treat your research as authorized. We will not pursue or support legal action against you for it, and we will not ask others to.

Good faith means: you access only what you need to demonstrate the issue, you do not degrade the service for others, you do not access, modify, or keep data that is not yours, and you give us a reasonable chance to fix the problem before you make it public. Test against your own accounts and your own data.

In scope

Findings that are more useful to us than a generic scanner: anything that touches the two invariants we treat as sacred, which are no false release of a vault, and the zero-knowledge boundary that keeps us from reading your content. Authorization flaws, replay, and account-takeover paths rank high.

Out of scope

None of this stops you from reporting something you think matters. If in doubt, send it. We would rather triage a borderline report than miss a real one.