Security
Security policy.
If you believe you have found a security vulnerability in Deniable, please report it privately so we can investigate and protect users before public disclosure.
How to report a vulnerability
Email support@deniable.net with the subject “Security report”. Include the affected URL or component, a clear description, reproduction steps, impact, and any proof-of-concept that can be shared safely. Please do not include real credentials, production customer data, or other sensitive personal information.
What to expect
- We aim to acknowledge a report within three business days.
- We will assess severity, reproduce the issue where possible, and keep the reporter informed about the next step.
- We will coordinate a reasonable disclosure timeline after the issue is understood and a fix or mitigation is available.
- Good-faith testing that avoids disruption, data access, persistence, spam, and social engineering is welcome.
Communication and encryption
Reports should be sent over HTTPS or by email. Deniable does not currently publish a public PGP key. If a report contains sensitive details, request a secure exchange channel before sending them. We will never ask you to send a password, API key, recovery token, or private dataset.
Out of scope
Denial-of-service testing, automated high-volume scanning, social engineering, physical attacks, spam, and testing against other users or third-party providers are out of scope. Stop testing immediately if you encounter data that does not belong to you and report only the minimum necessary evidence.
Related information
See the Privacy Policy, Terms of Service, and Contact page.
Last updated: 15 September 2026