Responsible Disclosure Policy

Last updated: July 24, 2026

Reporting a security issue

Vaultine is built to protect people's most private files, so we take security reports seriously. If you believe you've found a vulnerability, please tell us privately before disclosing it publicly.

Email: security@miciniti.com

Please include enough detail to reproduce the issue: the affected platform and app version, the steps involved, and any proof-of-concept. If you'd like to encrypt your report, ask and we'll share a key.

Our commitment

  • We'll acknowledge your report within 5 business days.
  • We'll keep you updated as we investigate and work on a fix.
  • We'll credit you for the discovery once the issue is resolved, if you'd like to be named.

Safe harbor

We will not pursue or support legal action against researchers who:

  • Make a good-faith effort to avoid privacy violations, data destruction, and service disruption.
  • Only interact with accounts or devices they own or have explicit permission to test.
  • Give us a reasonable opportunity to fix the issue before disclosing it publicly.
  • Do not exploit the issue beyond what is needed to demonstrate it.

Scope

In scope: the Vaultine apps (iOS, Android, macOS, Windows) and this website (vaultine.app).

Out of scope: third-party services Vaultine integrates with (for example, your own Dropbox account or the platform app stores), denial-of-service testing, social engineering, and physical attacks.

Rewards

Vaultine does not currently run a paid bug-bounty program. We offer public credit and our sincere thanks for responsibly disclosed, valid vulnerabilities.

Contact

security@miciniti.com