Skip to content

Security: OpenSelfHosting/OpenKey_server

Security

SECURITY.md

Security policy

Report vulnerabilities in OpenKey Server privately. Do not open a public GitHub issue for exploitable bugs.

Include the version/commit, steps to reproduce, and impact. We aim to acknowledge reports within 7 days.

The API is zero-knowledge: it stores ciphertext only. Master passwords and plaintext vault keys must never be sent to this service.

There aren't any published security advisories