Incident Support
Document Vault incident support protects the user's vault first. This page explains how privacy, security, provider, account, support evidence, and release escalations are triaged.
When to use this path
Use incident support for suspected exposure of secrets, credentials, OAuth tokens, purchase or account identifiers, vault metadata, document content, provider behavior, subscription account issues, App Review questions, release QA escalations, diagnostics questions, or future support tooling questions.
Intake rules
Collect only minimum necessary facts: platform, app build, OS version, active provider, feature area, visible redacted error state, and last safe action taken. Do not send PINs, passwords, one-time codes, OAuth tokens, private keys, RevenueCat keys, Supabase keys, App Store Connect keys, raw email addresses, Apple IDs, Google account identifiers, provider object ids, local file paths, document hashes, receipts, transaction ids, purchase tokens, billing records, document images, OCR text, translations, filenames, folders, tags, packets, generated PDFs, identity documents, financial documents, or medical documents unless support confirms a narrowly redacted sample is necessary.
Triage and containment
DeadStick Digital classifies incidents by affected surface: vault data, local storage, sync provider, subscription account, App Store review, diagnostics, release evidence, or documentation. Possible privacy or security incidents should stop routine sharing of the raw artifact and move to a redacted owner-reviewed path.
What this page does not claim
This incident support guidance does not claim a certified incident-response program, CUI authorization, FedRAMP authorization, Section 508 conformance, VPAT/ACR completion, government procurement readiness, or FIPS validation.
Contact
Use the DeadStick Digital message form and mark the first line of the message as Document Vault security or privacy support.