TiniDrop takes reports of security issues seriously. Please do not open a public GitHub issue for a vulnerability.
Email hello@tinidrop.com with:
- A description of the issue
- Steps to reproduce
- Impact (who can do what)
- Any proof-of-concept as a description, not as a live exploit against customer data
We will acknowledge receipt and keep you updated.
In scope: tinidrop.com, *.tinidrop.app, the public CLI in TiniDrop/cli.
Out of scope: social engineering, physical attacks, third-party services we do not control, and load testing that degrades the service.
If you act in good faith, avoid privacy violations, and give us a reasonable chance to fix the issue before public disclosure, we will not pursue legal action related to the report.
See SECURITY.md.