Security posture

Small static attack surface, explicit file trust boundaries.

Implemented controls

What integrity digests do not do

A digest detects accidental or deliberate payload changes after creation. It does not authenticate the participant, prove who created a file, encrypt content, establish consent, guarantee malware-free surrounding storage, or stop an authorized holder from copying the file.

User-controlled risk

Researchers control card text, study information, notes, response files, export destinations, devices, backups, transfer channels, and retention. Use encrypted and managed endpoints where appropriate, limit folder access, avoid direct identifiers, verify recipients, and follow organizational incident procedures.

Report a vulnerability

Email socialreminderinfo@gmail.com with a concise description, affected version/URL, reproduction steps, and impact. Do not include live participant data, exploit unrelated systems, cause disruption, or publish details before a reasonable remediation window. The prepared release also publishes /.well-known/security.txt.

Out of scope

General UX feedback, unsupported old browsers, user-authored research content, lost local files, compromised devices, hosting-provider availability, and legal/compliance questions are not vulnerabilities in the static runtime, though support may still document them.

No security guarantee: these controls reduce selected risks. They do not promise that the product, host, browser, device, transfer channel, or research process is secure for every threat model.