Skip to content
Frameleaf
    • Library & timelineEvery photo and video, in order
    • Search & AIFind anything by describing it
    • People & petsFaces recognised on your server
    • Memories & placesRediscover moments and maps
    • SharingPartners, spaces and links
    • Photo editorNon-destructive, with versions
    • StudioA full video editor, built in
    • For photographersIngest, proof, edit and deliver
    • Library careDuplicates, repairs and trash
    • PrivacyLocked content and what stays home
  • Demo
    • iPhone & iPadNative, written in Swift
    • AndroidNative, written in Kotlin
    • Web appThe full library in any browser
    • NAS appsUnraid, Synology and TrueNAS
    • Frameleaf CloudOptional services for your server
    • Remote accessReach home without open ports
    • Cloud backupEncrypted off-site copies
    • Buddy backupBack up to a friend's server
    • Cloud GPUHeavy AI jobs, paid by use
    • Sign inManage and open your servers
  • Pricing
  • Docs
  • Sign in to Frameleaf Cloud
  • Get Frameleaf
Sign inGet Frameleaf
Legal and policiesPolicies

Security Policy

Last updated October 3, 2026

On this page
  1. 1. Reporting a vulnerability or security incident
  2. 2. Security boundaries
  3. 3. Authorized Cloud research scope
  4. 4. Other products and excluded activity
  5. 5. Research rules and accidental access
  6. 6. Safe harbour
  7. 7. Response and remediation targets
  8. 8. Coordinated disclosure
  9. 9. Personal-data incidents
  10. 10. Contact and changes

Frameleaf welcomes good-faith reports of security vulnerabilities. This Policy explains our security boundaries, how to report a problem, the research we authorize and how we respond. The Security, Retention and Deletion Schedule and applicable Data Processing Addendum state our contractual security and incident obligations. This Policy does not create an additional uptime or recovery guarantee.

1. Reporting a vulnerability or security incident

Report privately to [email protected], with “Security report” in the subject, or contact us through https://frameleaf.app. You do not need a paid account to report an issue. For suspected active compromise, indicate that clearly in the subject and describe the immediate risk.

Please include:

  • The affected product, hostname, endpoint or software version.
  • A concise description, reproducible steps and the security impact you believe is possible.
  • The time of the observation, preferably in UTC, and relevant request identifiers.
  • A minimal demonstration using your own accounts and test data, with sensitive values removed.
  • A safe contact method and whether you wish to receive public credit.

Do not send usable credentials, private keys, full payment-card details, unrelated personal data or unnecessary private media. If a report needs sensitive evidence, first ask us to arrange an appropriate secure transfer method. Do not put exploit details in a public issue before coordinated disclosure.

For a compromised customer account, preserve relevant records, stop exposing affected credentials and contact support. Do not destroy your only recovery copy while attempting to contain an incident.

2. Security boundaries

Frameleaf Library runs on infrastructure controlled by its administrator. That administrator is responsible for the host, network, updates, permissions, local database and source media. Frameleaf Cloud provides separate account, connectivity, managed backup and selected processing services. It is not a hosted replacement for the running Library.

Remote-access relay forwards the encrypted TLS session to the Library without decrypting its application payload. Routing hostnames, connection information and usage measurements remain visible. Cloud account, identity and API services process the requests sent to those separate endpoints.

Managed Cloud Backup uses storage-provider server-side encryption with customer-provided keys. The Library sends the key over HTTPS to the storage endpoint for content operations; the processor performs encryption and decryption. The Cloud coordination service does not receive the usable bucket key through the ordinary backup protocol. Optional escrow stores a passphrase-wrapped envelope. This is not a claim that the storage processor never receives a usable key or readable content.

Buddy Backup encrypts recovery blocks and metadata on the source before transfer to a paired customer-operated server. Cloud coordinates authorization and connections. Confidentiality protection does not guarantee that a peer stays online or retains its disks, and a lost recovery key can make intact data unreadable.

Cloud AI processes readable selected inputs at its authorized processing system. Depending on the selected job, those inputs can include prepared previews, full images, video or audio. Selected AI content is uploaded directly to an ephemeral processing worker. Uploaded content and container-local working data are deleted immediately when the job finishes, and the processing container is destroyed. Frameleaf does not retain a stopped container or a separate post-job upload archive. The destroyed container and its uploaded content cannot be recovered through the service. Cloud AI also requires its own authorization. Backup or relay activation is not authorization for AI analysis.

Frameleaf will apply reasonable access controls, administrative authentication, logging, credential protection and incident handling within its responsibility. Encryption does not protect against every compromised endpoint, authorized administrator, stolen session or lost key. We do not assert a certification or an absolute security guarantee through this Policy.

3. Authorized Cloud research scope

Subject to the rules below, research is authorized against the following Frameleaf-operated services when they are active and under Frameleaf’s control:

  • frameleaf.cloud, the account site, and its account.frameleaf.cloud redirect.
  • id.frameleaf.cloud, the identity service.
  • api.frameleaf.cloud, the Cloud API, including backup provisioning, credentials, usage, recovery and lifecycle operations.
  • The regional backup endpoints listed below, within the backup-specific authorization described here.
  • ml.eu.frameleaf.cloud and ml.na.frameleaf.cloud, where the regional processing endpoint is enabled.
  • Frameleaf-operated relay infrastructure under *.relays.frameleaf.cloud and Frameleaf-operated authoritative name servers for frameleaf.net.
  • status.frameleaf.cloud, to the extent operated and controlled by Frameleaf.

Regional backup endpoints

The following Frameleaf backup hostnames are included for research into Frameleaf-controlled DNS configuration, service integration, credential scoping and access controls, using only your own authorized test accounts, buckets and data:

  • s3.ap-northeast-1.backup.frameleaf.cloud.
  • s3.ap-northeast-2.backup.frameleaf.cloud.
  • s3.ap-southeast-1.backup.frameleaf.cloud.
  • s3.ap-southeast-2.backup.frameleaf.cloud.
  • s3.ca-central-1.backup.frameleaf.cloud.
  • s3.eu-central-1.backup.frameleaf.cloud.
  • s3.eu-central-2.backup.frameleaf.cloud.
  • s3.eu-south-1.backup.frameleaf.cloud.
  • s3.eu-west-1.backup.frameleaf.cloud.
  • s3.eu-west-2.backup.frameleaf.cloud.
  • s3.eu-west-3.backup.frameleaf.cloud.
  • s3.us-central-1.backup.frameleaf.cloud.
  • s3.us-east-1.backup.frameleaf.cloud.
  • s3.us-east-2.backup.frameleaf.cloud.
  • s3.us-west-1.backup.frameleaf.cloud.
  • s3.us-west-2.backup.frameleaf.cloud.

These hostnames are DNS-only aliases maintained in Frameleaf’s Cloudflare DNS zone and route to the storage provider; their inclusion does not mean Cloudflare proxies or stores backup content. Associated _acme-challenge records may be examined through ordinary public DNS queries to assess Frameleaf’s configuration. They are certificate-validation records, not additional storage endpoints.

This authorization covers the Frameleaf-controlled aspects of the backup service. It does not authorize attacks on the storage provider’s shared infrastructure, certificate-validation systems, other tenants or provider administrative services. Testing that requires authority from the storage provider must also comply with that provider’s authorization. Reports about Frameleaf’s backup integration are welcome even when the underlying storage is supplied by a third party.

Listing a hostname does not assert that its service is enabled for every customer or region, or that every aspect of a third-party system to which it points is within Frameleaf’s authority. If ownership or scope is uncertain, obtain clarification before testing it.

A customer’s Library hostname, custom domain, peer server, storage bucket or account is not included merely because it connects through Frameleaf. Use only accounts, servers and data you own or have express written permission to test. Our authorization does not replace the owner’s or hosting provider’s authorization.

4. Other products and excluded activity

Vulnerabilities in Frameleaf Library code may be reported through the same contact. Reproduce them on an installation you control and follow any applicable repository security policy. This Policy does not grant access to other people’s Library installations. Reports concerning Frameleaf applications, frameleaf.app or help.frameleaf.app are also welcome, but those systems are not included in this Cloud testing authorization without separate permission.

Do not perform:

  • Denial-of-service, load, volume or destructive testing, or spam.
  • Social engineering, phishing, physical attacks or attempts to obtain another person’s credentials.
  • Credential stuffing, broad brute-force attacks, persistence, malware installation or movement into unrelated systems.
  • Extraction, alteration, deletion or retention of another person’s data beyond the minimum unavoidable observation needed to recognize an issue.
  • Testing of payment, email, hosting, storage or other third-party infrastructure without that provider’s authorization.

A scanner finding without demonstrated impact, a missing header alone or self-XSS may not establish an actionable vulnerability. You may still report a credible concern; do not escalate to harmful testing just to prove severity. Report suspected problems in Frameleaf’s integration with a provider to us, while directing vulnerabilities in the provider’s own service to that provider.

5. Research rules and accidental access

Use the least intrusive method needed, minimize requests and respect rate limits. Do not incur charges on another customer’s account or manipulate payments to obtain funds. Use test data and avoid interfering with availability, billing, backups or recovery access.

If you unexpectedly encounter another person’s information, stop the affected testing, do not browse further or download additional data, and report the event promptly. Retain only the minimum necessary non-sensitive description. Coordinate secure handling and deletion of any unavoidable evidence; do not redistribute it.

Testing that starts within scope must stop if continuing would violate these rules. Ask us before attempting a step that could affect customer data or service availability.

6. Safe harbour

For good-faith research conducted within this Policy and the authority Frameleaf can grant, Frameleaf considers the activity authorized and will not initiate or support legal action against you for that compliant activity under its terms or applicable anti-hacking laws. An accidental encounter with data does not by itself remove this protection if you promptly stop, minimize access and report it as required above.

If a third party questions compliant research, Frameleaf will explain that it was authorized under this Policy where lawful and appropriate. Frameleaf cannot bind an independent owner, provider, regulator or law-enforcement authority, waive another person’s rights or authorize access to systems outside its control. This protection does not cover extortion, deliberate data misuse or activity outside the stated scope.

7. Response and remediation targets

Step Target
Acknowledge a report Within 3 business days of receipt
Initial triage and severity assessment Within 7 calendar days of receipt
Critical vulnerability remediation or effective mitigation Within 7 calendar days after confirmation
High-severity vulnerability remediation or effective mitigation Within 30 calendar days after confirmation
Medium- or low-severity remediation Within 90 calendar days after confirmation

These are operational targets, not a promise that every report can be reproduced or permanently fixed within that period. We prioritize actual risk, exploitation, customer impact and available mitigations. Where a target cannot be met, we will explain the material limitation and provide an updated plan when doing so is safe and lawful. A mitigation can reduce immediate risk while a permanent fix is developed.

We will provide meaningful updates during remediation and coordinate attribution with you. Public credit is optional and does not require revealing your identity. There is no paid bounty programme under this Policy; submitting a report does not create a payment entitlement.

8. Coordinated disclosure

Please allow up to 90 calendar days from the report for investigation and remediation before publishing actionable technical details. Earlier disclosure may be agreed after a fix or mitigation is available. If more time is needed, we will explain why and seek a specific extension rather than treating the request as an indefinite prohibition.

Coordinate the timing and level of technical detail to reduce risk to customers who have not yet updated. Do not publish credentials, private content or information identifying affected customers without lawful authority. This process does not restrict legally protected reporting to regulators, law enforcement or advisers, or disclosure required by law.

9. Personal-data incidents

A vulnerability report is not automatically evidence of a personal-data breach. Frameleaf will assess credible incidents, contain harm, determine the affected information and provide notices required by applicable law and the Agreement.

For Customer Personal Data covered by the DPA, Frameleaf will notify the customer without undue delay and no later than 72 hours after becoming aware of a qualifying breach, unless a shorter mandatory deadline applies. Initial information may be supplemented as the investigation proceeds. Regulatory and individual notification duties have their own legal thresholds and deadlines; this is not a promise to wait 72 hours or to notify every authority and individual in every case.

Research response targets do not extend a statutory incident-notification deadline. Reports will be handled with access limited to the necessary investigation, remediation and legal purposes under the Privacy Notice and Security Schedule.

10. Contact and changes

Security contact: [email protected] or frameleaf.app.

Postal correspondence: Frameleaf, Inc., 14 Wall Street, Suite 2000, New York, NY 10005, United States. Telephone: +1 (332) 287-1911.

We may update the authorized scope and procedures prospectively. Changes do not retroactively withdraw the safe harbour for research that complied with the version in force when it occurred. A material new risk may require us to ask you to stop ongoing testing while we coordinate a safe approach.

More in Policies

  • Acceptable Use PolicyLawful use, abuse, protecting our infrastructure, private-content safeguards and enforcement.
  • Copyright and Abuse PolicyCopyright notices and counter-notices, intimate-image reports and repeat infringement.
  • Refund PolicyWhen purchases, subscriptions and AI credits are refunded, and app store purchases.
  • Trademark PolicyHow you may and may not use the Frameleaf name and logos.
  • Law Enforcement and Subpoena PolicyHow we respond to government and legal requests for data.

All legal documents

Frameleaf

A photo and video library for home servers. The Frameleaf Library community edition is open source under AGPLv3.

GitHub

Features

  • Library & timeline
  • Search & AI
  • People & pets
  • Memories & places
  • Sharing
  • Photo editor
  • Studio
  • For photographers
  • Library care
  • Privacy

Apps

  • iPhone & iPad
  • Android
  • Web app
  • NAS apps

Cloud

  • Frameleaf Cloud
  • Remote access
  • Cloud backup
  • Buddy backup
  • Cloud GPU
  • Pricing
  • Sign in to Frameleaf Cloud
  • Status

Get started

  • Get Frameleaf
  • Try the demo
  • Switch to Frameleaf
  • Install guide
  • Documentation
  • FAQ
  • Open source
  • Photo credits

Legal & policies

  • All legal documents
  • Terms of Service
  • Privacy Notice
  • Acceptable Use
  • Refund Policy
  • Security Policy
  • Cookies
© 2026 Frameleaf. Frameleaf Library community edition licensed under AGPLv3.