NeoShield Security logo NeoShield Security Quantum X

// security

Security and responsible disclosure

How we protect your data, what we store, and how to report a vulnerability. Last reviewed: 2026-06-26.

Minimal data

Accounts store only your email address. We do not sell data or run third-party trackers by default. You can export or delete your account data from your dashboard.

Zero-knowledge vault

Quantum Vault encrypts in your session only. Your passphrase and plaintext are never stored, transmitted in the clear, or logged. A lost passphrase is unrecoverable by design.

Encryption

TLS in transit with HSTS. At rest and in the vault we use AES-256-GCM (authenticated) with an Argon2id key. AES-256 keeps ~128-bit strength even against a quantum adversary.

Hardened by default

Strict Content-Security-Policy, secure session cookies (HttpOnly, SameSite, Secure), CSRF protection, login lockout, honeypot and abuse blocking, and SSRF guards on outbound fetches.

Responsible disclosure policy

We welcome reports from security researchers and will not pursue legal action for good-faith research that respects this policy.

Scope

The neoshieldsecurity.com web application and its public APIs.

Please do

Please don't

How to report

Email security@neoshieldsecurity.com or use the contact form. Machine-readable details are published at /.well-known/security.txt.

Compliance posture