Document Vault

Incident Support

Document Vault incident support protects the user's vault first. This page explains how privacy, security, provider, account, support evidence, and release escalations are triaged.

When to use this path

Use incident support for suspected exposure of secrets, credentials, OAuth tokens, purchase or account identifiers, vault metadata, document content, provider behavior, subscription account issues, App Review questions, release QA escalations, diagnostics questions, or future support tooling questions.

Intake rules

Collect only minimum necessary facts: platform, app build, OS version, active provider, feature area, visible redacted error state, and last safe action taken. Do not send PINs, passwords, one-time codes, OAuth tokens, private keys, RevenueCat keys, Supabase keys, App Store Connect keys, raw email addresses, Apple IDs, Google account identifiers, provider object ids, local file paths, document hashes, receipts, transaction ids, purchase tokens, billing records, document images, OCR text, translations, filenames, folders, tags, packets, generated PDFs, identity documents, financial documents, or medical documents unless support confirms a narrowly redacted sample is necessary.

Triage and containment

DeadStick Digital classifies incidents by affected surface: vault data, local storage, sync provider, subscription account, App Store review, diagnostics, release evidence, or documentation. Possible privacy or security incidents should stop routine sharing of the raw artifact and move to a redacted owner-reviewed path.

What this page does not claim

This incident support guidance does not claim a certified incident-response program, CUI authorization, FedRAMP authorization, Section 508 conformance, VPAT/ACR completion, government procurement readiness, or FIPS validation.

Contact

Use the DeadStick Digital message form and mark the first line of the message as Document Vault security or privacy support.