Skip to content
FanVault
Home / Security & Disclosure
🛡️ 256-Bit Encrypted Vault Protocol · Responsible Disclosure

Security & Vulnerability Disclosure

FanVault protects heartfelt memories, milestone letters, and creator financial ledgers. We maintain defense-in-depth security standards and actively welcome collaboration with the global security research community.

Core Security Controls

🔒
256-Bit Encryption

Letters and sensitive database records are encrypted with AES-256 at rest, and all web traffic is forced through TLS 1.3 with strict HSTS.

💳
PCI-DSS Level 1 via Stripe

Payment card data is tokenized straight in your browser. FanVault servers never view, touch, or store raw credit card numbers.

🔑
Passwordless Magic Links

Creators authenticate via cryptographically random, single-use magic login tokens that expire in 30 minutes, preventing credential stuffing.

🎫
SHA-256 Token Hashing

Fan letter claim keys are hashed using SHA-256 before storage. Even in the event of an internal audit, secrets remain irreversible.

🛡️
Defense-in-Depth

Strict CSRF verification, prepared SQL statements, XSS auto-escaping in Blade templates, and rate-limiting on sensitive endpoints.

☁️
Isolated Cloud Infrastructure

Hosted on dedicated AWS EC2 infrastructure with automated security patches, encrypted snapshots, and isolated production environments.

Responsible Vulnerability Disclosure Program (VDP)

We believe responsible disclosure is vital to a safe internet. If you are an independent security researcher and discover a vulnerability in our application, we encourage you to report it to us immediately.

Our Safe Harbor Commitment:

If you conduct your research in good faith, avoid violating the privacy of other users, do not disrupt platform availability, and give us reasonable time to resolve the issue before public disclosure, FanVault will not pursue legal action against you or seek law enforcement intervention.

Scope & Boundaries

✓ In Scope:
  • getfanvault.com and primary web application
  • Authentication bypasses & privilege escalation
  • SQL injection & data exfiltration risks
  • Stored or reflected Cross-Site Scripting (XSS)
  • Stripe webhook signature bypasses
  • Unauthenticated access to sealed letters
✕ Out of Scope:
  • Volumetric Denial of Service (DDoS) attacks
  • Spamming or automated brute-forcing
  • Social engineering or phishing of staff
  • Third-party services (e.g. Stripe, AWS endpoints)
  • Missing DNSSEC or cosmetic HTTP headers without exploit

How to Submit a Security Report

Please submit all vulnerability disclosures directly to our Security Operations Team at security@getfanvault.com.

Please include in your report:
1. A descriptive title and vulnerability category (e.g., IDOR, SQLi, Auth Bypass)
2. Detailed step-by-step reproduction instructions or a minimal Proof of Concept (PoC)
3. Potential impact assessment and affected endpoints
4. Your preferred name or handle for security acknowledgment
24 Hours Initial receipt acknowledgment
72 Hours Engineering triage & severity rating
Continuous Status updates until patch deployment

Researcher Hall of Fame

We publicly acknowledge researchers who responsibly disclose verified security vulnerabilities:

Security Operations Desk: security@getfanvault.com