Report a security issue

SenseVault

If you believe you have found a security vulnerability in SenseVault, please report it privately so it can be fixed before it is made public.

Email: support@saseclabs.tech
Please include what the issue is, how to reproduce it, and the app + Android versions.

What to expect

This is a solo project, so please be patient — but every report is read and taken seriously. Genuine issues are fixed and shipped as a Play update as quickly as is reasonable.

Scope

SenseVault is offline — no servers, no accounts, no internet permission — so there is no API to attack or traffic to intercept. The app is honest that it cannot protect data on a rooted or malware-infected device, or a device unlocked in an attacker's hands; those are not treated as vulnerabilities. A vulnerability is the vault being readable without the master password, secrets leaking beyond their intended lifetime, weaker encryption than described, or a crafted backup file causing data loss.

Please give a reasonable chance to fix an issue before disclosing it publicly, and test only against your own device and data.