Security is fundamental to CHOPPNOTE.
If you believe you have discovered a security vulnerability, please report it responsibly.
Security contact
For an active or urgent security incident, use the same address with the subject “URGENT SECURITY INCIDENT”:
Please include
Where possible, include:
- a description of the vulnerability,
- affected URL or component,
- steps required to reproduce the issue,
- potential impact,
- screenshots or proof-of-concept information that does not expose third-party private data.
Please do not
Please do not:
- access private information belonging to other users,
- intentionally degrade or interrupt the service,
- perform destructive testing,
- use social engineering,
- publicly disclose an unresolved vulnerability before we have had reasonable time to investigate it.
Sensitive information
Do not send passwords, authentication secrets, private keys, recovery codes or other credentials by ordinary email.
If sensitive information is required to investigate a vulnerability, contact us first so an appropriate transfer method can be arranged.
Our response
We aim to acknowledge legitimate security reports as quickly as reasonably possible.
We will investigate reported vulnerabilities, assess their severity and work toward remediation based on their potential impact.
Security model
CHOPPNOTE is designed around client-side encryption.
For private notes, the application is designed so that:
- note plaintext is encrypted in the sender's browser,
- the server receives ciphertext rather than plaintext,
- the decryption key is not stored with the ciphertext,
- encrypted notes expire automatically,
- a note is designed to become unavailable through CHOPPNOTE after its first successful reveal.
No software system can provide absolute security.
CHOPPNOTE cannot prevent recipients from copying, photographing, recording or otherwise preserving information after it has been decrypted on their device.