SenseVault
If you believe you have found a security vulnerability in SenseVault, please report it privately so it can be fixed before it is made public.
This is a solo project, so please be patient — but every report is read and taken seriously. Genuine issues are fixed and shipped as a Play update as quickly as is reasonable.
SenseVault is offline — no servers, no accounts, no internet permission — so there is no API to attack or traffic to intercept. The app is honest that it cannot protect data on a rooted or malware-infected device, or a device unlocked in an attacker's hands; those are not treated as vulnerabilities. A vulnerability is the vault being readable without the master password, secrets leaking beyond their intended lifetime, weaker encryption than described, or a crafted backup file causing data loss.
Please give a reasonable chance to fix an issue before disclosing it publicly, and test only against your own device and data.