Security and vulnerability reports
Last updated: 25 September 2026.
Bosonoo is operated by Bosonoo Pty Ltd, ACN 699 900 019, ABN 60 699 900 019, NSW, Australia. Send security concerns to admin@bosonoo.com, using “Security report” in the subject. Do not include passwords, API keys or unnecessary personal information.
Security boundaries and practical precautions
Bosonoo separates public pages, browser-local file tools and account-authorised services. Workspace access may require approval in addition to verified sign-in. Editors and automated tools are intended to operate only within the permissions and file scope they have been given. These controls reduce risk; they are not a promise that the service cannot fail or be compromised.
Protect your identity-provider account and use available strong authentication. Keep your browser and device updated, review the permissions you grant and avoid using a shared browser profile for sensitive work. Signing out does not necessarily erase temporary files saved by that profile.
Export important work and keep an independent backup. Check saves, conversions, AI edits and downloaded files before relying on them. A pending save, a browser recovery copy or an AI task’s success message is not a guarantee that all expected content was stored correctly.
Ordinary hosted files and remote AI are not a general end-to-end encrypted service. A folder lock or PIN does not necessarily encrypt its contents. If an eligible Vault encryption feature is offered, read its limits and preserve what you need to unlock or export the content. No certification, independent security audit, uninterrupted service or universal recovery capability is claimed by this page.
Reporting a vulnerability
Give us a concise description, the affected public URL or feature, the time observed, the impact you believe is possible and the smallest safe reproduction. Screenshots or redacted logs can help. If sensitive evidence is necessary, first ask how to provide it; do not assume ordinary email is an appropriate place for it.
Use your own account and data for any investigation. Stop if you unexpectedly encounter another person’s data, an unexpected permission or service instability. Report what you observed without accessing more data to prove the issue.
Do not modify or delete someone else’s data, establish persistence, exfiltrate information, disrupt availability, send unsolicited messages, socially engineer staff or users, or test a third-party provider without its permission. Public access to a service is not general authorisation to scan, attack or bypass it. Contact us first if a test could affect availability or another person.
Handling a report
We may ask for clarification, investigate, mitigate the issue or coordinate with an affected provider. Please give us a reasonable opportunity to investigate before releasing details that would expose users to avoidable risk, and discuss disclosure timing with us. This is a request for responsible coordination, not a restriction on rights that the law protects.
We do not currently promise a bug bounty, a fixed response time, a reward, legal immunity or permission to act on behalf of our providers. We do not ask you to waive rights or accept a blanket confidentiality agreement merely to report a concern.
For a compromised account, suspected wrongful charge or lost file, contact admin@bosonoo.com with the relevant non-secret identifiers and approximate time. See the Privacy policy for information about records, access requests and complaints.