Trust center

ZipPigeon trust center

A single place for the operational details people check before trusting a file-transfer product with sensitive documents.

Security model

ZipPigeon protects file chunks in the browser with XChaCha20-Poly1305 before upload. Migrated v3 account recipients can use X-Wing HPKE combining X25519 with ML-KEM-768, while v3 records use Ed25519 + ML-DSA-65 dual signatures.

  • Security model: /security-model
  • Detailed security page: /security
  • Crypto design inside the signed-in app: /crypto

Privacy and terms

ZipPigeon still processes operational metadata so delivery, abuse prevention, audit events, and reliability work. The privacy and terms pages describe what is processed, what should stay out of reach, and what users are responsible for.

  • Privacy: /privacy
  • Terms: /terms
  • Pricing and limits: /pricing

Vulnerability disclosure

Security researchers can report issues to security@zippigeon.com with affected routes, reproduction steps, impact, and synthetic evidence where possible. ZipPigeon also publishes a machine-readable security.txt file under /.well-known/security.txt.

  • Contact: security@zippigeon.com
  • Use synthetic test data when possible
  • Do not access other users files, keys, or account data

Frequently asked questions

Is ZipPigeon formally audited or certified?

Not publicly. ZipPigeon should not be described as SOC 2, HIPAA, ISO 27001, or independently audited until those assessments are completed and published for the deployed service.

Where should security issues be reported?

Send reports to security@zippigeon.com and include affected routes, steps to reproduce, impact, and whether synthetic test data was used.

Send the file. Keep control of the link.

Use ZipPigeon when a file needs to reach the right person without becoming another attachment or shared folder to clean up later.

Open signed-in sender