Security at Vaulith

Vaulith deletes files for a living — so it is engineered like the security product it has to be. This page explains what we promise, and how to tell us if we ever fall short.

Our security architecture, in plain language

For reviewers and IT teams, our Security Whitepaper maps this architecture to controls in detail — the no-egress design, the signing & notarization chain, the recoverable-deletion model, our subprocessors, and what’s honestly still on the roadmap. Deploying across a fleet? See Vaulith for Teams.

Reporting a vulnerability

If you believe you've found a security issue in the Vaulith desktop app, our website, dashboard, or infrastructure, we want to hear about it — before anyone else does.

Safe harbor for good-faith research

We will not pursue legal action against researchers who: act in good faith, avoid privacy violations and service disruption, do not access or modify other users' data, give us reasonable time to remediate before public disclosure, and do not exploit findings beyond what is necessary to demonstrate them.

Out of scope: denial-of-service testing, social engineering of our staff or users, spam, and findings that require physical access to a victim's unlocked device.

We don't currently run a paid bounty program — but we credit researchers (with permission) in release notes, and we take every report seriously. This policy was last updated July 2026.