Responsible disclosure

Responsible disclosure for a privacy-first secret sharing service.

Your secrets are not read, profiled, trained on, indexed, or retained beyond configured expiry. Support can help with billing cancellation, but cannot restore lost secrets or lost access.

01

How to report

Use the contact form with a security topic and send a clear reproduction using test data only. Include endpoint, impact, browser or client, approximate timestamps, and whether the issue affects secret confidentiality, billing, access control, or availability.

  • Use test secrets only
  • No real credentials
  • Include concrete steps

02

Scope boundaries

Do not attack other users, exfiltrate secrets, bypass billing for real use, perform destructive testing, persist access, scan at high volume, social-engineer users, or publish findings before coordinated remediation.

  • No customer data access
  • No destructive load
  • No public disclosure before fix

03

What to expect

Shhhs will triage valid reports, ask for clarification when needed, and coordinate remediation. There is no public bug bounty program or guaranteed payout at this stage.

  • Coordinated remediation
  • No bounty promise
  • No secret data in reports

FAQ

Does Shhhs process secrets with AI?

No. There is no AI processing on secret content.

Can Shhhs recover a secret?

No. Secret recovery would weaken the privacy model.

What can support recover?

Support can help cancel billing after billing validation, but cannot restore account access or secret content.