Security model
ZipPigeon protects file contents in the browser before upload, stores encrypted chunks and encrypted manifests, and prepares access through account-bound shares, secure links, or constrained anonymous one-time sends.
- Security model: /security-model
- Detailed security page: /security
- Crypto design inside the signed-in app: /crypto
Current public limits
The public service is free for now, with tighter limits for no-account anonymous sends and configurable deployment limits for signed-in managed transfers.
- Signed-in sends: browser-encrypted uploads with account invites, secure links, expiration, transfer status, archive, and audit events.
- Default encrypted upload part size: 16 MiB. Default server part ceiling: 10,000 encrypted parts before deployment or storage policy applies.
- Secure-link policy: sender-selected download limits up to the deployment maximum, with a default maximum of 100 downloads.
- Service API: available from the app for accounts with API access; service tokens default to 90 days and are capped at 365 days unless configured otherwise.
- Anonymous one-time sends: 50 MB total, 5 files, 80 encrypted parts, one download, and a 24-hour maximum expiry by default.
- Anonymous default expiry: 6 hours unless the sender chooses a shorter or longer allowed window.
- Anonymous file policy: high-risk executable, script, installer, and active-content extensions are blocked before upload.
Privacy and terms
ZipPigeon still processes operational metadata so delivery, abuse prevention, audit events, and reliability work. The privacy and terms pages describe what is processed, what should stay out of reach, and what users are responsible for.
- Privacy: /privacy
- Terms: /terms
- Pricing and limits: /pricing
Vulnerability disclosure
Security researchers can report issues to security@zippigeon.com with affected routes, reproduction steps, impact, and synthetic evidence where possible. ZipPigeon also publishes a machine-readable security.txt file under /.well-known/security.txt.
- Contact: security@zippigeon.com
- Use synthetic test data when possible
- Do not access other users files, keys, or account data
Compliance and roadmap status
Formal compliance attestations, DPA terms, customer-managed keys, public key transparency, enterprise SSO enforcement, and bring-your-own infrastructure are not yet public offers. Roadmap pages describe planned direction separately from shipped guarantees.
- Product roadmap: /roadmap
- Anonymous sharing limits and roadmap: /anonymous-sharing-roadmap
- Contact for diligence questions: privacy@zippigeon.com
Frequently asked questions
Is ZipPigeon formally audited or certified?
Not publicly. ZipPigeon should not be described as SOC 2, HIPAA, ISO 27001, or independently audited until those assessments are completed and published for the deployed service.
Is anonymous sharing available?
Yes. Anonymous one-time sharing is available with tight limits: 50 MB total, 5 files, 80 encrypted parts, one download, and a 24-hour maximum expiry by default.
Where should security issues be reported?
Send reports to security@zippigeon.com and include affected routes, steps to reproduce, impact, and whether synthetic test data was used.