Skip to content
qeva.
FeaturesSecurityArchitectureSelf-hostFree forever
Star on GitHub
FeaturesSecurityArchitectureSelf-hostFree foreverStar on GitHub
Legal

Security & Responsible Disclosure

Last updated: July 29, 2026

Qeva is a password manager, so security is not a feature - it is the product. If you have found a vulnerability, we want to hear from you and we will work with you to fix it.

Reporting a vulnerability

Please report security issues privately, not in public GitHub issues. Email us at security@qeva.app. Our machine-readable contact details are published at /.well-known/security.txt.

What to include

  • A clear description of the issue and its potential impact.
  • Step-by-step instructions to reproduce it, including affected versions.
  • Any proof-of-concept code, logs, or screenshots that help.
  • How you would like to be credited, if you want public acknowledgement.

Our commitment to you

  • We will acknowledge your report within 3 business days.
  • We will keep you updated as we investigate and work on a fix.
  • We will not pursue legal action for good-faith research that follows this policy (a safe harbour for responsible disclosure).
  • We are happy to credit you once a fix is released, if you would like that.

Scope

In scope:

  • The Qeva software in our source repository.
  • This website.

Out of scope:

  • Self-hosted instances operated by others - report those to their operators.
  • Third-party services and infrastructure we do not control.
  • Volumetric denial-of-service, spam, and social-engineering attacks against staff or users.

Coordinated disclosure

We follow coordinated disclosure. Please give us a reasonable window - typically up to 90 days - to release a fix before any public write-up, and coordinate the timing with us so users can update safely.

Encryption

If you would like to encrypt your report, ask us for a current PGP key when you make first contact.

qeva.

Open source, self-hosted password management. Free forever.

Product

FeaturesSecurityArchitectureSelf-hostingFree forever

Project

GitHubDocumentationContributingLicense (AGPL)

Community

DiscussionsReport an issueSponsorContact

Legal

PrivacyTermsSecurityCookies
© 2026 Qeva. Open source under the AGPL-3.0 license.