Security

Report it privately. Get credited publicly.

Found a vulnerability? It reaches us fastest by email — plain text or PGP-encrypted, whatever the details need. We read every report, we fix before we publish, and when the fix ships, your name goes on this page permanently if you want it there.

Please don't send security reports through the general contact or ideas forms — this address reaches the right person directly.

What to send

The short version is fine. The repro is better.

  • What you were testing — the app version, the platform and OS.
  • What you did, what you saw, and what you expected instead.
  • The smallest set of steps that reproduces it.
  • A proof-of-concept or screenshots, if you have them.
  • A way to reach you, if you want credit or updates. Anonymous is fine too.

You do not need a polished writeup to write in. A half-formed report that lets us reproduce the problem is worth more than a perfect one that arrives never.

How it works

Report it. We fix it. You get named.

Reach us directly

Email founder@prevonprivacy.com — plain text is fine, or encrypted with our PGP key if the details are sensitive. Say what you found, how to reproduce it, and what you think an attacker could do with it.

We confirm, then we fix

If you included a way to reply, you get an acknowledgment — and updates as we work, not silence. We ask for reasonable time to investigate and ship a fix before any public disclosure, and we will name the date once we know it.

Stay inside the vault — yours, not other people's

Test against your own device and data. Do not access, modify, or exfiltrate another user's vault, even to prove a point — that crosses from research into the exact harm this architecture exists to prevent.

You get credited, not ignored

Every confirmed, responsibly disclosed vulnerability earns a permanent entry below once the fix has shipped — your name or handle, what class of issue it was, and the date it was resolved. Or stay anonymous; the report speaks for itself.

Safe harbor

Good-faith research is protected. In writing.

If you test against your own devices and your own vault, never touch another person's data, and give us a reasonable window to fix before going public, we will not pursue legal action over your research — and we will not ask anyone else to pursue it for us. Good-faith security research is authorized here; it is how the vault gets stronger.

If a test ever looks to us like it went past that line, you will hear it from us first — never from a court.

The list

Confirmed reports.

Nobody's here yet.

Prevon is in private beta, and no vulnerability report has been confirmed and fixed yet. The moment one is, this space becomes the first entry — permanently, not quietly removed once the news cycle passes.