Informal translation. This is an informal English translation of the German policy. In case of any discrepancy, the German version is authoritative.

Security & Responsible Disclosure

Heritavo manages sensitive data under a zero-knowledge model. Security reports are our highest priority. This page describes how you can report a vulnerability and what expectations you can place on our handling.

How to report issues

Preferably by email to security@heritavo.com. If that channel is unreachable, you can also reach us at support@heritavo.com.

Machine-readable version of this policy: /.well-known/security.txt.

What to include in your report

What we commit to

What we ask of you

Scope

In scope are all Heritavo-operated hosts under heritavo.com. Other Heritavo domains (e.g. heritavo.ch, heritavo.de) are mere redirects to heritavo.com and have no separate scope. Out of scope are linked third parties, pure spam/phishing reports, and automated scanner findings without concrete impact.

Zero-knowledge model

Heritavo encrypts vault contents client-side before upload. The server has no access to the master key. Even a full database leak gives an attacker no access to decrypted vault data — provided the user password is strong enough to resist Argon2id brute force. Findings that break this invariant we handle with the highest priority.

Version: May 2026