Security & Responsible Disclosure
Qeva is a password manager, so security is not a feature - it is the product. If you have found a vulnerability, we want to hear from you and we will work with you to fix it.
Reporting a vulnerability
Please report security issues privately, not in public GitHub issues. Email us at security@qeva.app. Our machine-readable contact details are published at /.well-known/security.txt.
What to include
- A clear description of the issue and its potential impact.
- Step-by-step instructions to reproduce it, including affected versions.
- Any proof-of-concept code, logs, or screenshots that help.
- How you would like to be credited, if you want public acknowledgement.
Our commitment to you
- We will acknowledge your report within 3 business days.
- We will keep you updated as we investigate and work on a fix.
- We will not pursue legal action for good-faith research that follows this policy (a safe harbour for responsible disclosure).
- We are happy to credit you once a fix is released, if you would like that.
Scope
In scope:
- The Qeva software in our source repository.
- This website.
Out of scope:
- Self-hosted instances operated by others - report those to their operators.
- Third-party services and infrastructure we do not control.
- Volumetric denial-of-service, spam, and social-engineering attacks against staff or users.
Coordinated disclosure
We follow coordinated disclosure. Please give us a reasonable window - typically up to 90 days - to release a fix before any public write-up, and coordinate the timing with us so users can update safely.
Encryption
If you would like to encrypt your report, ask us for a current PGP key when you make first contact.