Draft · version 4 September 2026
Security
Report vulnerabilities responsibly: do not retrieve other users' content, disrupt availability, or publish details before the risk can be addressed.
Technical model
PassToView uses Argon2id password hashing, server-side encryption at rest, per-publication data keys, HttpOnly host-only cookies, CSRF protection, attempt limits, and security headers. It is not end-to-end encryption and does not protect against full compromise of the production server together with its keys.
How to report
The security@passtoview.ru mailbox is planned but has not yet been verified. A verified email will be published here and in security.txt after manual testing.