We take security seriously. If you discover a security vulnerability, please follow these steps:
- Do NOT open a public issue
- Email the details to the maintainers privately
- Include steps to reproduce the vulnerability
- Allow up to 48 hours for initial response
This application implements several security measures:
- AES-256-GCM - Military-grade symmetric encryption
- PBKDF2 - 100,000 iterations for key derivation
- Web Crypto API - Browser-native cryptographic operations
- All encryption/decryption happens client-side
- Server never receives unencrypted data
- Passcodes never leave the browser
- File metadata is encrypted before storage
- Passcode-protected file sharing
- Optional burn-after-read
- Configurable expiry times
- Download tracking and revocation
- Pre-signed URLs for direct S3 access
- No server-side file processing
- Supabase Row Level Security (RLS)
- Use strong, unique passcodes for each shared file
- Enable burn-after-read for sensitive files
- Set short expiry times when possible
- Verify recipient identity before sharing links
We regularly update dependencies to patch known vulnerabilities. Run pm audit to check for issues.