The policy we wrote before we needed it.
If Copywarden ever has a security incident, this page is the contract for how we will behave — written while calm, published in advance, so that in the moment there is nothing to decide and nothing to spin.
The design principle: one complete disclosure, not a drip
The clearest lesson of the last decade of breach communications is LastPass (2022): the damage to trust came less from the breach itself than from the drip — an initial notice that minimized, a November update that expanded it, and the full scope (encrypted vault backups taken) arriving in a late-December disclosure months after the intrusion began. Each installment made the previous one look like an evasion.
We commit to the opposite: when we disclose, we disclose once, completely. If the investigation later surfaces material new facts, we update the same single advisory with a dated, visible changelog — we do not publish a softened first act and a worse sequel.
What we commit to
1. First public notice within 72 hours
Within 72 hours of confirming any incident that affects user data, shipped-binary integrity, our signing keys, or our update or distribution channels. The first notice says plainly: what we know, what we do not yet know, and what (if anything) you should do right now. It will not claim the investigation is finished when it isn't.
2. A single, complete disclosure
When the investigation concludes, containing: what happened, in plain language, with a timeline (intrusion, detection, containment); exactly which data and systems were affected — and which were not; what the encryption did and did not protect, specifically whether encrypted-at-rest clipboard data or wrapped keys were exposed and what an attacker could do with them; the root cause, what we fixed, and what we changed so the class of bug is gone; what affected users must do, first, in one short list; and credit to the reporter, if the issue came through coordinated disclosure and they wish it.
3. No minimizing language
No "out of an abundance of caution," no "sophisticated threat actor" as an excuse, no burying the update at a quiet hour. If the news is bad, the words will be bad.
4. How you will hear about it
All of the following, at the same time: a banner on copywarden.com and a dated advisory page; the in-app update notes of any release that ships a fix; and direct email to affected Copywarden Account holders — for users of the app without an account, the site and the in-app update channel are the notification paths.
5. Fixes ship before or with the disclosure
Wherever a fix exists. Where none exists yet, the disclosure says so and gives the mitigation honestly.
What an "incident" can even mean here
Copywarden is local-first: clipboard data is encrypted on your Mac, and there is no Copywarden server holding it. Optional sync stores only ciphertext, sealed on-device, in your own iCloud database. That shapes the realistic incident classes: a vulnerability in the app itself — the most likely case; compromise of our build, signing, or update pipeline; compromise of the website or download channel; and compromise of the Copywarden Account infrastructure — which is designed so that servers hold ciphertext and never the keys, a claim any disclosure would have to address head-on rather than hide behind.
We will never say "your data was not affected" as a reflex. We will say it only when we can explain why it is true.
Reporting a vulnerability
Intake: email security@copywarden.com. Our machine-readable RFC 9116 security.txt lists the same contact.
Acknowledgment: we respond within 3 business days, and we will tell you our assessment and intended timeline rather than go silent.
Coordinated disclosure: we ask for a reasonable window to fix before publication and will agree on the timeline with you, not dictate it.
Safe harbor for good-faith research
If you make a good-faith effort to comply with this policy while researching Copywarden — no access to other people's data, no service disruption, no extortion — we will not pursue or support legal action against you for that research, and we will not report you for it. We consider security research done this way a contribution, we will credit you in the advisory if you want credit, and we will say thank you in public.
Revisions to this policy are dated and the changelog published on this page. Precedent referenced: LastPass security incident disclosures, August–December 2022 — cited as a communications precedent, not as a technical comparison.