Back to eOCI VaulteOCI Vault

Security

How to report a vulnerability without exposing identity documents or production secrets.

Report a vulnerability

security@e-oci.in is the intended security-reporting route. Send a minimal technical description and reproduction steps only.

Do not include sensitive material

Do not send identity documents, document fields, QR or barcode payloads, PINs, vault exports, private keys, certificates, passwords, tokens, or screenshots containing personal information.

Current security boundary

The native vault is local and encrypted, with device-only Keychain protection and foreground/inactivity locking. No app can guarantee absolute security on a compromised or already-unlocked device.

Unofficial companion. Not a Government of India service. Keep your original source document and passport.