Security

Security is the design, not a feature.

IDOP is a format for documents that contain code. This page says what we do to keep that safe, what we deliberately do not do, and how to report a problem.

§ 01Documents

How a document is kept in its place.

Validated before it runs

The reader checks the whole file — ZIP structure, names, sizes, manifest, the code it contains — before any of it executes. A file that fails any check does not run at all.

Sandboxed

A document runs in an isolated frame on an opaque origin. It cannot read the reader, your other documents, your session or your keys.

No network unless you say so

A document has no fetch. If it needs a service, it declares the exact address; you are asked, and only that address is allowed.

Keys never reach a document

The reader adds your key to a request after its checks, and only for the addresses you pinned the key to.

A budget on every session

An approved document cannot loop and spend your API credit without limit.

Explicit saves

Nothing is written into a file until you save, and every save is validated again before it replaces the file.

§ 02IDOP Cloud

How the cloud keeps accounts apart.

  • Every database query is checked by row-level security in the database itself, for every request — including ours.
  • Passwords and sessions are handled by a dedicated authentication service; we never store or see a password.
  • File contents are never directly addressable; every read goes through the service, which is what makes revoking a link real.
  • Share-link passwords are stored only as one-way hashes; after ten wrong answers a link locks for fifteen minutes.
  • Our servers do not open, parse or analyse your files — except when an AI assistant you connected asks to read or change a document, and then only that document, with your own access.
  • All traffic is encrypted in transit; our storage providers encrypt data at rest.

§ 03Plainly

What we do not claim.

  • A document’s title and author are declared by whoever made it and are not verified. Publisher signatures are under research.
  • A document can display anything, including a fake sign-in page. Open documents from people you trust.
  • Anyone who can open a document can keep a copy.
  • We hold no security certifications at this stage. When we do, they will be listed here.

§ 04Disclosure

Reporting a vulnerability.

Write to security@idoplabs.com with a description, steps or a minimal file that reproduces the issue, and the impact you expect.

  • Do not access other people’s data, and do not degrade the service while testing.
  • Give us reasonable time to fix the issue before disclosing it.
  • We acknowledge reports within three working days and keep you informed until the issue is resolved.
  • We do not take legal action against good-faith research that follows these rules.

We do not currently run a paid bug bounty. Machine-readable contact: /.well-known/security.txt. Design of the format’s protections: specification §17.