ContactVault Logo ContactVault ALPHA v.1.0

Security / Responsible Disclosure

Last updated: 1 November 2025

Our approach

Responsible disclosure policy

We welcome good‑faith research and reports that help us protect applicants and recipients. If you follow the rules below, we won’t pursue or support legal action against you for your research.

Rules of engagement

Scope

Out of scope

How to report

Email contactvault@tuta.io with the subject “Vulnerability report.” If you need to share sensitive details, tell us and we’ll provide a PGP key for encrypted follow‑up.

Include clear steps to reproduce, affected endpoints, expected vs. actual behavior, any screenshots or PoC, and the impact assessment. Please add your handle if you’d like public thanks after remediation.

Assessment process & timelines

Testing tips

Thanks for helping us keep applicants safe.