Skip to content

PUBLIC INFORMATION

Security at WipeWire

Current protections, responsible reporting guidance, and work that remains before public launch.

Current protections

  • Authenticated gateway access and organization-scoped permission checks.
  • Encrypted, versioned credential storage; secrets remain server-side.
  • Separate rate limits for API, chat, Discord, and pairing traffic.
  • Duplicate-mutation and idempotency protection for risky actions.
  • Same-origin checks for custom cookie-authenticated web mutations.
  • Structured security logs that exclude request bodies, authorization headers, chat content, pairing secrets, Steam tokens, and Discord secrets.
  • Automated dependency review, code analysis, secret scanning, and container scanning.

Responsible reporting

Do not test against another team, access data you do not own, disrupt service, or disclose a suspected issue publicly. Stop as soon as you confirm a possible exposure and preserve only the minimum evidence needed to explain it.

A dedicated security-reporting address and response target have not been activated. During private testing, use the contact channel provided directly by the WipeWire operator. Do not send passwords, tokens, private keys, or Steam Guard codes.

Known pre-launch work

  • Replace the isolated legacy packages behind the remaining moderate dependency advisories.
  • Complete a live backup-and-restore drill.
  • Complete organization deletion, export, and cross-team isolation probes against production-like data.
  • Finalize a coordinated vulnerability-disclosure contact and response process.

Security limitations

No internet service can promise absolute security. WipeWire is not an emergency or guaranteed raid-detection system. If a connected credential may be exposed, revoke it at the source and notify the operator through your existing private-testing contact.