# Reporting a security problem in ObscuraOS. # # Everything on this site runs in the browser and there is no account system, # so the interesting reports are client side: a way to make a tool leak the # file it is working on, a bypass of the content security policy, a stored # cross-site scripting path through a document name or a pasted document, or # a flaw in how a vault is encrypted. Those matter to us and we want them. # # Write to the address below. Tell us what you did, what happened, and what # you expected. A proof of concept helps. We will reply. # # We do not run a paid bounty. We will credit you by name on the security # page if you want the credit, and we will not threaten you for looking. Contact: mailto:security@obscuraos.com Contact: mailto:hello@obscuraos.com Expires: 2027-09-09T00:00:00.000Z Preferred-Languages: en Canonical: https://obscuraos.com/.well-known/security.txt Policy: https://obscuraos.com/security