Security
Found something? Tell us first
Driven holds a copy of things people have copied, which makes it worth attacking. If you find a way to reach that data, we would rather hear it from you than read about it later.
Last updated 12 August 2026.
How to report
Email hello@drivenmemory.com with "Security report" in the subject. Include what you found, the build number it affects, and enough detail to reproduce it. A rough proof of concept is worth more than a scanner printout.
Please do not open a public issue or post the details before we have had a chance to fix it.
What you can expect back
One person reads that inbox, so the honest answer is days rather than hours. You should get an acknowledgement within three working days and an assessment within seven. If something is confirmed and serious, fixing it goes to the front of the queue and a build follows as soon as it is ready.
There is no bug bounty. There is no money behind this project yet, and promising a payment that may not arrive would be worse than saying so now. Credit on this page is offered gladly if you want it, and declined just as gladly if you do not.
In scope
Driven Clipboard for Windows, Driven SmartClip for Android, and the hosts drivenmemory.com, dl.drivenmemory.com and go.drivenmemory.com. Anything that exposes a user's stored items to another process or another person is the category we care about most.
Out of scope
Denial of service and traffic flooding, social engineering of the developer, physical attacks, spam or rate-limit reports, and findings that only affect a third party's own systems such as Cloudflare, GitHub or Google Play. Reports produced entirely by an automated scanner with no demonstrated impact will usually be acknowledged and closed.
The unsigned installer is known and disclosed rather than a finding. So is the update check described on the privacy page.
Safe harbour
If you research in good faith, stay inside the scope above, use only your own machine and your own data, avoid degrading the service for anyone else, and give us reasonable time to fix what you found before publishing, we will not pursue legal action against you and will not ask anyone else to. If you are unsure whether something crosses a line, ask before you do it.
How to verify a build before you run it
Every published build has its SHA-256 printed on the download page, read live from a file published beside the installer rather than typed into the page by hand, and a link to the antivirus scan for that exact hash. On Windows:
Get-FileHash .\Driven-Clipboard-Setup.exe -Algorithm SHA256
If the hash does not match the one on the download page, do not run the file, and please tell us.
What the design already does for you
There is no account, no server holding your items and no database of ours to breach, because everything you save stays in local storage on your own device. That removes an entire class of incident rather than defending against it. It also means the realistic threat is local: another process on your machine, or someone with physical access to it. That is where reports are most useful.
Contact
hello@drivenmemory.com, read by the person who built it.