PrivShare

Security research

Responsible Disclosure

PrivShare welcomes good-faith reports for vulnerabilities that affect the confidentiality, integrity, or availability of the service.

Report A Vulnerability

Send enough detail to reproduce the issue safely. Do not send real secrets, production user data, URL fragments, raw passwords, private keys, or signed transfer URLs.

Email security@priv-share.com with a clear description, reproduction steps, impact, affected route or component, and safe proof using your own test data. A machine-readable version of this contact is published at /.well-known/security.txt. Testing rules by area, guidelines, and researcher credits are on the security research hall of fame.

Report contact

Send vulnerability reports to security@priv-share.com. Do not include real secrets.

Response target

PrivShare aims to acknowledge reports within 3 business days and provide a remediation or triage-update timeline within 14 calendar days.

Research credit

Valid reports may receive public credit with the researcher permission. PrivShare does not publish a name without permission.

No paid bounty

We do not currently have a paid bug bounty. Responsible security research is still welcome.

In Scope

Use only accounts, shares, files, and recipient email addresses that you control.

  • Authentication and account session management.
  • Authorization and owner-only account routes.
  • Share creation and retrieval APIs.
  • Expiration, revocation, and burn-after-reading behavior.
  • Password-protected share unlock and verifier handling.
  • Client-side encryption and key handling.
  • Encrypted file handling.
  • ID enumeration and lifecycle disclosure issues.
  • Race conditions.
  • XSS, CSRF, SSRF, injection, API validation, and information disclosure.
  • Recipient notification safety using email addresses you control.

Out Of Scope

These activities are not authorized without prior written approval.

  • Accessing, modifying, deleting, or exfiltrating other users' accounts, shares, files, metadata, or emails.
  • Denial-of-service, load, or destructive testing.
  • Spam or unsolicited recipient email testing.
  • Social engineering, phishing, or physical attacks.
  • Attacks against third-party providers except as directly necessary to show a PrivShare vulnerability with safe evidence.
  • Public disclosure before PrivShare has had a reasonable opportunity to investigate and remediate.

Safe Harbor

PrivShare does not pursue legal action against researchers who follow this policy and act in good faith.

  • Test only your own accounts and own test shares.
  • Avoid privacy violations and avoid accessing data that is not yours.
  • Stop testing and report promptly if you encounter another user's data.
  • Keep vulnerability details confidential until PrivShare has investigated and remediated or provided a disclosure timeline.
  • Use safe evidence, such as screenshots of your own test account or redacted request examples.