Security model
ZipPigeon protects file chunks in the browser with XChaCha20-Poly1305 before upload. Migrated v3 account recipients can use X-Wing HPKE combining X25519 with ML-KEM-768, while v3 records use Ed25519 + ML-DSA-65 dual signatures.
- Security model: /security-model
- Detailed security page: /security
- Crypto design inside the signed-in app: /crypto
Privacy and terms
ZipPigeon still processes operational metadata so delivery, abuse prevention, audit events, and reliability work. The privacy and terms pages describe what is processed, what should stay out of reach, and what users are responsible for.
- Privacy: /privacy
- Terms: /terms
- Pricing and limits: /pricing
Vulnerability disclosure
Security researchers can report issues to security@zippigeon.com with affected routes, reproduction steps, impact, and synthetic evidence where possible. ZipPigeon also publishes a machine-readable security.txt file under /.well-known/security.txt.
- Contact: security@zippigeon.com
- Use synthetic test data when possible
- Do not access other users files, keys, or account data