Skip to content

Vulnerability Disclosure

We take the security of Onetime Secret seriously and welcome reports from security researchers and users. If you believe you’ve found a vulnerability, please let us know so we can investigate and address it.

Email security@onetimesecret.com with the details of your finding. If you need to share a proof of concept or other sensitive details, mention it in your message and we’ll coordinate a secure channel.

Please include where practical:

  • A clear description of the issue and its potential impact.
  • Steps to reproduce, including affected URLs, parameters, or requests.
  • Any proof-of-concept code, screenshots, or logs.
  • The environment where you observed it (for example, the hosted service or a self-hosted version and its version number).

We ask that you:

  • Give us a reasonable opportunity to investigate and remediate before any public disclosure.
  • Avoid privacy violations and service disruption — do not access, modify, or delete data that isn’t yours, and avoid automated testing that degrades the service for others.
  • Use test accounts and your own data wherever possible.

In return, we will acknowledge reports made in good faith, keep you updated on our progress, and work to resolve confirmed issues promptly. We will not pursue action against researchers who follow these guidelines.

  • Hosted service: the Onetime Secret application and its regional endpoints.
  • Self-hosted: the open-source project on GitHub. For self-hosted deployments, please also confirm whether the issue is present on the latest released version.

For general questions, account help, or non-security bugs, use support@onetimesecret.com or our feedback form instead.