Security & Vulnerability Disclosure
NFDGames LLC welcomes good-faith security research on OpenDrop. This page is our coordinated-disclosure policy, scope, severity rubric, and safe-harbor terms.
How to report
Send your report by email. PGP-encrypted submissions are welcome.
Backup: support@nfdgames.com
Subject prefix:
[SECURITY]security.txt: /.well-known/security.txt
What to include
- The product and version (e.g., "OpenDrop iOS 1.0.0+18", "desktop server 1.0.0 on macOS 14.5").
- A concise description of the vulnerability and the security impact.
- Reproduction steps, with sample inputs, request/response captures, or a minimal proof-of-concept.
- Whether you intend to disclose publicly, and on what timeline.
- Whether you would like credit in our acknowledgments below.
What we commit to
- Acknowledge receipt within 3 business days.
- Triage and initial assessment within 7 business days, with a severity rating and a target fix window.
- Keep you informed as we investigate. We will not surprise you with disclosure timelines.
- Coordinate public disclosure with you. Default 90-day disclosure window from triage, extendable for hardware/supply-chain issues.
- Credit you in our acknowledgments (Hall of Fame, below) unless you request otherwise.
Scope
In scope:
- OpenDrop mobile apps for iOS and Android (the App Store and Google Play builds).
- OpenDrop desktop server (Python/PySide6) for Windows, Linux, and the in-development macOS build.
- Our Cloudflare Worker control plane (
opendrop.n-fantinodyer.workers.dev), its KV-backed device-registration API, and the anonymous free-relay-token mint that issues short-lived, rotating tokens for free-tier relay access. - Our self-hosted file-relay infrastructure used for cross-network transfers (the Fly.io relay for Pro subscribers and the Oracle Cloud relay for the free tier and Pro failover).
- Our peer-to-peer (WebRTC) connection layer and self-hosted STUN servers used for direct cross-network transfers.
- The OpenDrop wire protocol and end-to-end encryption (ChaCha20-Poly1305 IETF AEAD, HKDF-SHA256, HMAC-SHA256).
- nfdgames.com web properties, the marketing site, blog, support form, and OpenDrop pages.
- Our Firebase Authentication configuration and OAuth flows.
- The OpenDrop CLI mode and headless server.
Out of scope:
- Vulnerabilities in third-party services we depend on (Cloudflare, Fly.io, Oracle Cloud, Firebase, Apple, Google Play, Stripe, RevenueCat). Please report those to the providers directly under their own disclosure programs.
- Reports based on outdated client versions. Please confirm against the latest published release before submitting.
- Theoretical attacks without a demonstrable security impact.
- Self-XSS, clickjacking on pages with no sensitive state, and other low-impact UI-only issues.
- Volumetric denial-of-service findings produced by automated scanners or load tests.
- Missing security headers on the marketing site that don't lead to a demonstrable compromise (CSP, HSTS-preload, etc., appreciated as hardening suggestions, but generally not eligible for our acknowledgments).
- Reports requiring physical access to a victim's unlocked device.
- Social-engineering attacks against NFDGames LLC staff or vendors.
Severity rubric
We use a simple four-tier rubric, not CVSS. The tier dictates response speed and the order in which we ship fixes.
| Tier | Examples | Target fix window |
|---|---|---|
| Critical | Account takeover; key-recovery against the E2EE primitives; remote code execution on the desktop server; bypass of the protocol-version gate that would let a downgraded or non-conforming client transfer plaintext. | 7 days from triage |
| High | Authenticated cross-account data exposure; HMAC forgery; CSRF on a state-changing endpoint; secrets leakage in logs; downgrade attack on the wire protocol. | 21 days from triage |
| Medium | Stored XSS in marketing pages without auth context; SSRF without remote impact; partial information disclosure (e.g. metadata leaks beyond what the privacy policy describes); race conditions with limited impact. | 45 days from triage |
| Low | Hardening recommendations; missing security headers on non-sensitive pages; minor information disclosure (e.g., software version in error messages); rate-limit gaps without amplification. | Best-effort, no commitment |
Safe-harbor terms
If you follow this policy in good faith, NFDGames LLC will not pursue or support any legal action against you, and will treat your research as authorized for the purposes of:
- The U.S. Computer Fraud and Abuse Act (CFAA), 18 U.S.C. § 1030.
- The U.S. Digital Millennium Copyright Act (DMCA), 17 U.S.C. § 1201 (anti-circumvention).
- The South Carolina Computer Crime Act and analogous state laws.
- Our Terms of Service Section 5 ("Acceptable Use") prohibition on unauthorized access.
"Good faith" means you:
- Make a sincere effort to avoid privacy violations, data destruction, and interruption of service.
- Only access, copy, or modify accounts and data that you own or have explicit permission to test.
- Do not run automated scanning that could cause service degradation.
- Do not exfiltrate or retain data beyond what is necessary to demonstrate the vulnerability, and destroy any data obtained when the report is acknowledged.
- Give us a reasonable amount of time (per the severity rubric above) to fix the issue before publicly disclosing.
- Do not extort, threaten, or otherwise pressure NFDGames LLC.
This safe-harbor extends only to claims by NFDGames LLC. We cannot waive claims by third parties whose systems you may inadvertently touch (e.g., our cloud providers). When in doubt, ask first.
Compensation
OpenDrop is a one-person product and we do not currently operate a paid bug-bounty program. We compensate researchers in the following non-monetary ways:
- Acknowledgment in the Hall of Fame on this page (and in product release notes where the fix ships).
- A complimentary OpenDrop Pro subscription (lifetime) for any report we triage as Medium or higher.
- Direct line to me (founder, sole engineer) for follow-up research questions.
If your research uncovers something Critical with broad real-world impact and you would prefer monetary compensation in lieu of acknowledgment, contact us, we will negotiate in good faith case-by-case.
Hall of Fame
We thank the following researchers for responsibly disclosing security issues in OpenDrop:
No public disclosures yet, be the first.
What this policy is not
- It is not a service-level agreement. It does not promise that any particular finding will be fixed, only that we will respond and assess.
- It is not a guarantee of monetary reward. See "Compensation" above.
- It is not a license to test third-party systems. If your test path touches Cloudflare, Fly.io, Oracle Cloud, Firebase, Apple, or any other provider in our stack, you must comply with that provider's own policy in addition to ours.
- It does not authorize denial-of-service testing, social engineering, or physical-security testing under any condition.
Last updated: June 4, 2026 · security.txt · Privacy Policy · Terms