Report vulnerabilities in OpenKey Server privately. Do not open a public GitHub issue for exploitable bugs.
- Email: security@openselfhosting.com
- Or a private advisory under OpenSelfHosting
Include the version/commit, steps to reproduce, and impact. We aim to acknowledge reports within 7 days.
The API is zero-knowledge: it stores ciphertext only. Master passwords and plaintext vault keys must never be sent to this service.