Security Policy
Last updated: 2025
Reporting a Vulnerability
We take security seriously. If you discover a vulnerability in Ironlox, please report it to [email protected].
- Do not file a public issue for security vulnerabilities.
- Provide a detailed description with steps to reproduce.
- Include any relevant proof-of-concept code or screenshots.
- We will acknowledge your report within 48 hours.
- We follow a 90-day coordinated disclosure policy.
- Credit is given on our Hall of Fame for valid reports (opt-in).
- We do not offer a bug bounty program at this time.
Encryption Standards
All vault data is encrypted with AES-256-GCM before leaving the client device. Key derivation uses Argon2id (memory-hard, GPU-resistant). The server receives only encrypted blobs and a separate authentication hash derived with a different salt. The server never has access to plaintext data, master passwords, or encryption keys under any circumstances.
Infrastructure Security
- All traffic is encrypted in transit via TLS 1.3.
- API runs on Cloudflare Workers, benefiting from Cloudflare's DDoS protection and WAF.
- Database (D1) and blob storage (R2) are encrypted at rest by Cloudflare.
- Authentication uses short-lived JWT tokens (15-minute access, 7-day refresh).
- Rate limiting prevents brute-force and credential-stuffing attacks.
- Turnstile CAPTCHA protects signup and login endpoints from bots.
Supply Chain
We minimize third-party dependencies, particularly in the crypto package. All encryption uses the Web Crypto API (SubtleCrypto) — no third-party crypto libraries. Dependencies are pinned to exact versions and reviewed during updates.
PGP Key
You may encrypt sensitive reports to our PGP key. Download it below or fetch from keys.openpgp.org.
-----BEGIN PGP PUBLIC KEY BLOCK----- mQINBGdM3oMBEAC9Y5kq3F8xPm7R2jVvK6wHnT4sB1xWpL8mN9yQ0aF3dG5h I7jK0lM3nO1pQ2rS4tU6vW8xY0zA2B4cD6eF8gH0iJ2kL4mN6oP0qR2sT4uV6 wX8yZ0aB2cD4eF6gH8iJ0kL2mN4oP6qR0sT2uV4wX6yZ0aB2cD4eF6gH8iJ (placeholder — replace with real key before production) -----END PGP PUBLIC KEY BLOCK-----
Fingerprint: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
For reports that don't require encryption, use [email protected].