SpiderOak · Vulnerability Disclosure
Spideroak Vulnerability Disclosure
Vulnerability disclosure
SpiderOak runs a coordinated vulnerability disclosure program on Hackerone.
CompanySecurityZero TrustEncryptionAccess ControlIdentity and Access ManagementCryptographyDefenseAerospaceSpaceOpen-SourceEdge ComputingData ExchangeBackup and Storage
Program: Hackerone
Disclosure Policy
Security Contact
Source
Vulnerability Disclosure
generated: '2026-08-29'
method: searched
source: https://raw.githubusercontent.com/aranya-project/.github/main/SECURITY.md, https://spideroak.com/security-response/
provider: SpiderOak
program_published: true
note: 'probe-security-programs.py found nothing automatically because SpiderOak serves no /.well-known/security.txt
and runs no HackerOne/Bugcrowd/Intigriti program. The policy is real, it is just published at ordinary paths.
Upgraded to method: searched from the two documents below.'
policies:
- name: Aranya Project Security Policy
url: https://github.com/aranya-project/.github/blob/main/SECURITY.md
raw: https://raw.githubusercontent.com/aranya-project/.github/main/SECURITY.md
status: 200
last_updated: 10OCT2024
contact: securityreports@spideroak.com
scope: The Aranya open-source platform
reporting: Private email; public GitHub issues explicitly forbidden for vulnerabilities.
coordinated_disclosure: true
embargo: Requests "a reasonable amount of time to resolve the issue before any disclosure"; reserves the right
to disclose before resolution if appropriate.
supported_versions: The latest version or release is supported.
handling_process:
- Confirm the problem and determine affected versions
- Audit code for similar problems
- Prepare fixes for all still-supported releases
- Release security fix versions and update the public repository
requested_report_fields:
- Description of the vulnerability
- Aranya software version, hardware platform and OS version
- Logs and artifacts
- Steps to reproduce
- Potential impact
- Suggested mitigation or fix
- Reporter name/handle for credit
credit_offered: true
- name: SpiderOak Security Response
url: https://spideroak.com/security-response/
status: 200
scope: SpiderOak products (ONE, Groups, CrossClave, Semaphor)
response_time: Usually within 24 hours, certainly within 1 business day.
pgp: A public key is offered for encrypting sensitive reports.
credit_offered: true
published_advisories:
- date: '2017-09-28'
summary: SpiderOak ONE and Groups v6.4.0 — Share Room vulnerabilities.
- date: '2017-06-05'
summary: SpiderOak ONE and Groups v6.3.0 — potential active attack vectors found by security researchers.
defect_found: 'The contact address printed on this page is security@spideroak21.wpengine.com — a WP Engine staging
hostname leaked into production copy, not a deliverable SpiderOak address. The working contact is securityreports@spideroak.com
from the Aranya SECURITY.md. Worth reporting to the provider: a security company''s security-report address
currently points at its hosting provider''s staging domain.'
bug_bounty:
exists: false
note: No HackerOne, Bugcrowd or Intigriti program found; no paid bounty is advertised on either policy page.
security_txt:
exists: false
probed:
- url: https://spideroak.com/.well-known/security.txt
status: 404
- url: https://spideroak.one/.well-known/security.txt
status: 404
- url: https://aranya-project.github.io/.well-known/security.txt
status: 404
note: RFC 9116 security.txt would be a near-zero-cost addition given the policy already exists.
supply_chain:
note: The Aranya repos carry a supply-chain/ directory (cargo-vet) and a published vet specification at https://aranya-project.github.io/vet/,
plus release security controls at https://aranya-project.github.io/release-security-controls/ covering branch
protections, CI/CD workflows, environment protections and secrets management.
advisories_consumed:
- id: RUSTSEC-2026-0007
action: v4.1.1 patch release (2026-02-03) cut as a defensive measure; Aranya code does not directly trigger the
vulnerable path.
url: https://rustsec.org/advisories/RUSTSEC-2026-0007
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/spideroak-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.