Skip to content
Security bug reporting

Report a security bug, end-to-end encrypted.

Submit your finding through the form below. Your proof-of-concept files, reproduction steps, and any sensitive context reach the SendSafely security team encrypted on your device with OpenPGP/AES.

Bug reporting form

Submit your finding, get a fast triage.

Our security team will rate all submissions using the Bugcrowd Vulnerability Rating Taxonomy.

Refer to our Bug Bounty page for the complete program rules and eligibility requirements for receiving a cash reward.

SendSafely Bug Report

Questions? Send an email to support@sendsafely.com.

End-to-end encrypted

Your submission is encrypted before it leaves your browser.

The bug reporting form uses the SendSafely Dropzone widget. Attachments are encrypted on your device with OpenPGP/AES, and the platform stores that content as ciphertext only.

Audited annually under SOC 2 Type 2. The same split-key architecture that protects every customer file protects your proof of concept.

Compliance & certifications
SOC 2 Type 2 HIPAA PCI DSS GDPR CCPA
Client-side OpenPGP
Files are encrypted on the device before they ever leave it.
Split-key architecture
The decryption key is split so no single party—including SendSafely—can decrypt file contents on its own.
Full audit trail
Every send, recipient open, identity check, and download is logged with timestamps for compliance reporting.
Bug bounty program

Read the program rules before you submit.

Eligibility, scope, severity ratings, and standard payouts ($1,500 P1, $500 P2, $200 P3) are documented in the bug bounty program rules.