Responsible Disclosure Policy
Last updated: July 24, 2026
Reporting a security issue
Vaultine is built to protect people's most private files, so we take security reports seriously. If you believe you've found a vulnerability, please tell us privately before disclosing it publicly.
Email: security@miciniti.com
Please include enough detail to reproduce the issue: the affected platform and app version, the steps involved, and any proof-of-concept. If you'd like to encrypt your report, ask and we'll share a key.
Our commitment
- We'll acknowledge your report within 5 business days.
- We'll keep you updated as we investigate and work on a fix.
- We'll credit you for the discovery once the issue is resolved, if you'd like to be named.
Safe harbor
We will not pursue or support legal action against researchers who:
- Make a good-faith effort to avoid privacy violations, data destruction, and service disruption.
- Only interact with accounts or devices they own or have explicit permission to test.
- Give us a reasonable opportunity to fix the issue before disclosing it publicly.
- Do not exploit the issue beyond what is needed to demonstrate it.
Scope
In scope: the Vaultine apps (iOS, Android, macOS, Windows) and this website (vaultine.app).
Out of scope: third-party services Vaultine integrates with (for example, your own Dropbox account or the platform app stores), denial-of-service testing, social engineering, and physical attacks.
Rewards
Vaultine does not currently run a paid bug-bounty program. We offer public credit and our sincere thanks for responsibly disclosed, valid vulnerabilities.