Security

Last updated: October 5, 2026

LifeOS holds some of the most personal things people write down, so it's built so that we can't read them. This page explains how, what we're still working on, and how to tell us if you find a problem.

How your data is protected

What isn't end-to-end encrypted

Independent audit

We plan to commission an independent review of the encryption design and code and to publish the full report here. It hasn't happened yet, and we won't claim it has until the report is up. The design and the browser code that runs it are readable by anyone in the app's source.

Report a vulnerability

Email bradyfitllc@gmail.com with "LifeOS security report" in the subject. Please include steps to reproduce and what an attacker could achieve. We'll reply within 3 business days, keep you updated, and credit you here if you'd like.

Bug bounty

We pay for valid, previously unknown issues, at our discretion based on impact:

Ground rules

If you follow these rules, we won't pursue or support legal action against you for your research.

← Back to LifeOS