Report contact
Send vulnerability reports to security@priv-share.com. Do not include real secrets.
Security research
PrivShare welcomes good-faith reports for vulnerabilities that affect the confidentiality, integrity, or availability of the service.
Send enough detail to reproduce the issue safely. Do not send real secrets, production user data, URL fragments, raw passwords, private keys, or signed transfer URLs.
Email security@priv-share.com with a clear description, reproduction steps, impact, affected route or component, and safe proof using your own test data. A machine-readable version of this contact is published at /.well-known/security.txt. Testing rules by area, guidelines, and researcher credits are on the security research hall of fame.
Send vulnerability reports to security@priv-share.com. Do not include real secrets.
PrivShare aims to acknowledge reports within 3 business days and provide a remediation or triage-update timeline within 14 calendar days.
Valid reports may receive public credit with the researcher permission. PrivShare does not publish a name without permission.
We do not currently have a paid bug bounty. Responsible security research is still welcome.
Use only accounts, shares, files, and recipient email addresses that you control.
These activities are not authorized without prior written approval.
PrivShare does not pursue legal action against researchers who follow this policy and act in good faith.
Keep reading
Every security page links to the others so you can move through the full model without using the browser back button.