SpiderOak · Vulnerability Disclosure

Spideroak Vulnerability Disclosure

Vulnerability disclosure

SpiderOak runs a coordinated vulnerability disclosure program on Hackerone.

CompanySecurityZero TrustEncryptionAccess ControlIdentity and Access ManagementCryptographyDefenseAerospaceSpaceOpen-SourceEdge ComputingData ExchangeBackup and Storage
Program: Hackerone

Disclosure Policy

Security Contact

Source

Vulnerability Disclosure

spideroak-vulnerability-disclosure.yml Raw ↑
generated: '2026-08-29'
method: searched
source: https://raw.githubusercontent.com/aranya-project/.github/main/SECURITY.md, https://spideroak.com/security-response/
provider: SpiderOak
program_published: true
note: 'probe-security-programs.py found nothing automatically because SpiderOak serves no /.well-known/security.txt
  and runs no HackerOne/Bugcrowd/Intigriti program. The policy is real, it is just published at ordinary paths.
  Upgraded to method: searched from the two documents below.'
policies:
- name: Aranya Project Security Policy
  url: https://github.com/aranya-project/.github/blob/main/SECURITY.md
  raw: https://raw.githubusercontent.com/aranya-project/.github/main/SECURITY.md
  status: 200
  last_updated: 10OCT2024
  contact: securityreports@spideroak.com
  scope: The Aranya open-source platform
  reporting: Private email; public GitHub issues explicitly forbidden for vulnerabilities.
  coordinated_disclosure: true
  embargo: Requests "a reasonable amount of time to resolve the issue before any disclosure"; reserves the right
    to disclose before resolution if appropriate.
  supported_versions: The latest version or release is supported.
  handling_process:
  - Confirm the problem and determine affected versions
  - Audit code for similar problems
  - Prepare fixes for all still-supported releases
  - Release security fix versions and update the public repository
  requested_report_fields:
  - Description of the vulnerability
  - Aranya software version, hardware platform and OS version
  - Logs and artifacts
  - Steps to reproduce
  - Potential impact
  - Suggested mitigation or fix
  - Reporter name/handle for credit
  credit_offered: true
- name: SpiderOak Security Response
  url: https://spideroak.com/security-response/
  status: 200
  scope: SpiderOak products (ONE, Groups, CrossClave, Semaphor)
  response_time: Usually within 24 hours, certainly within 1 business day.
  pgp: A public key is offered for encrypting sensitive reports.
  credit_offered: true
  published_advisories:
  - date: '2017-09-28'
    summary: SpiderOak ONE and Groups v6.4.0 — Share Room vulnerabilities.
  - date: '2017-06-05'
    summary: SpiderOak ONE and Groups v6.3.0 — potential active attack vectors found by security researchers.
  defect_found: 'The contact address printed on this page is security@spideroak21.wpengine.com — a WP Engine staging
    hostname leaked into production copy, not a deliverable SpiderOak address. The working contact is securityreports@spideroak.com
    from the Aranya SECURITY.md. Worth reporting to the provider: a security company''s security-report address
    currently points at its hosting provider''s staging domain.'
bug_bounty:
  exists: false
  note: No HackerOne, Bugcrowd or Intigriti program found; no paid bounty is advertised on either policy page.
security_txt:
  exists: false
  probed:
  - url: https://spideroak.com/.well-known/security.txt
    status: 404
  - url: https://spideroak.one/.well-known/security.txt
    status: 404
  - url: https://aranya-project.github.io/.well-known/security.txt
    status: 404
  note: RFC 9116 security.txt would be a near-zero-cost addition given the policy already exists.
supply_chain:
  note: The Aranya repos carry a supply-chain/ directory (cargo-vet) and a published vet specification at https://aranya-project.github.io/vet/,
    plus release security controls at https://aranya-project.github.io/release-security-controls/ covering branch
    protections, CI/CD workflows, environment protections and secrets management.
advisories_consumed:
- id: RUSTSEC-2026-0007
  action: v4.1.1 patch release (2026-02-03) cut as a defensive measure; Aranya code does not directly trigger the
    vulnerable path.
  url: https://rustsec.org/advisories/RUSTSEC-2026-0007

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/spideroak-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.