maneuler / vault

SECURITY · UPDATED SEPTEMBER 21, 2026

Help us make private storage safer.

Vault is preview software. No independent security audit has been completed. Encryption, automated tests and this disclosure policy are not certification.

Report privately

Email ceo@maneuler.com with “Vault security report” in the subject. This is the current reporting contact while a dedicated security inbox is being arranged. No reporting PGP key is published yet; ask for a verified encrypted channel before sending sensitive technical details.

Include the platform and version, affected component, expected and actual behavior, and a minimal reproduction using made-up data. Never send a real vault, master passphrase, passwords, card details, private keys or authentication tokens.

Test only what you own

Use local builds, test accounts and synthetic vaults. Do not access other people's data, disrupt production, run denial-of-service tests, phish users or attack hosting providers. If you encounter another person's information, stop and report the minimum necessary description without copying or retaining it.

How we handle reports

We aim to acknowledge reports within five business days, investigate impact and coordinate remediation and disclosure with the reporter. This is a response target, not a guaranteed service level. If you have not heard back, resend the report to the same contact. Reporter credit is optional and requires consent.

Know the boundaries

The app encrypts KDBX files locally and does not upload vault contents to Maneuler. Unlocked data can still be exposed by a compromised browser, extension, app, device or web deployment. JavaScript cannot guarantee complete memory erasure. Clipboard contents, old backups and recipients' existing copies are outside the vault's control.

Wi-Fi sync requires explicit main-device approval and pinned TLS. Same-subnet checks cannot prove physical proximity. Current imports support uncompressed Argon2id KDBX4 within documented limits. iOS device validation and independent audit remain pending.

Bounty status

We welcome responsible reports. A paid bounty program is not active; do not assume a reward, contractual safe harbor or authorization beyond your own local test environment. Read the draft bounty scope and its launch requirements.