Security
Security is the design, not a feature.
IDOP is a format for documents that contain code. This page says what we do to keep that safe, what we deliberately do not do, and how to report a problem.
§ 01Documents
How a document is kept in its place.
Validated before it runs
The reader checks the whole file — ZIP structure, names, sizes, manifest, the code it contains — before any of it executes. A file that fails any check does not run at all.
Sandboxed
A document runs in an isolated frame on an opaque origin. It cannot read the reader, your other documents, your session or your keys.
No network unless you say so
A document has no
fetch. If it needs a service, it declares the exact address; you are asked, and only that address is allowed.Keys never reach a document
The reader adds your key to a request after its checks, and only for the addresses you pinned the key to.
A budget on every session
An approved document cannot loop and spend your API credit without limit.
Explicit saves
Nothing is written into a file until you save, and every save is validated again before it replaces the file.
§ 02IDOP Cloud
How the cloud keeps accounts apart.
- Every database query is checked by row-level security in the database itself, for every request — including ours.
- Passwords and sessions are handled by a dedicated authentication service; we never store or see a password.
- File contents are never directly addressable; every read goes through the service, which is what makes revoking a link real.
- Share-link passwords are stored only as one-way hashes; after ten wrong answers a link locks for fifteen minutes.
- Our servers do not open, parse or analyse your files — except when an AI assistant you connected asks to read or change a document, and then only that document, with your own access.
- All traffic is encrypted in transit; our storage providers encrypt data at rest.
§ 03Plainly
What we do not claim.
- A document’s title and author are declared by whoever made it and are not verified. Publisher signatures are under research.
- A document can display anything, including a fake sign-in page. Open documents from people you trust.
- Anyone who can open a document can keep a copy.
- We hold no security certifications at this stage. When we do, they will be listed here.
§ 04Disclosure
Reporting a vulnerability.
Write to security@idoplabs.com with a description, steps or a minimal file that reproduces the issue, and the impact you expect.
- Do not access other people’s data, and do not degrade the service while testing.
- Give us reasonable time to fix the issue before disclosing it.
- We acknowledge reports within three working days and keep you informed until the issue is resolved.
- We do not take legal action against good-faith research that follows these rules.
We do not currently run a paid bug bounty. Machine-readable contact: /.well-known/security.txt. Design of the format’s protections: specification §17.