Security
Last updated 4 October 2026. Wormhole is a product of vwork Digital Inc., Chilliwack, British Columbia.
Wormhole is built so that a breach of our servers would not expose what people send through private forms. This page lists what protects your data, and how to report a problem.
Encryption
- Private forms are end-to-end encrypted. The sender's browser encrypts answers and files (ECDH P-256 and AES-256-GCM) to keys that only the recipient's enrolled devices or agent endpoint hold. We never have those keys.
- Encrypted submissions sit in a per-submission mailbox that deletes itself when the recipient confirms receipt, or at the deadline. Live hand-offs are never stored.
- Personal links can carry secret details for the person you send them to. The key lives only in the part of the link after the #, which browsers never send to a server.
- Everything travels over HTTPS with HSTS.
On the web
- A strict Content Security Policy with a fresh nonce on every request: only our own scripts can run, the site cannot be framed, and forms can only post back to Wormhole. You can check the live grade on Mozilla Observatory.
- No analytics, trackers or third-party fonts. The one outside script is Cloudflare Turnstile, an invisible bot check on sign-up, sign-in and public forms.
- Rate limits on every public endpoint, and form passwords lock for 15 minutes after repeated wrong guesses.
Accounts and keys
- Sign in with a passkey, a one-time email link, or a password of at least 12 characters. Email is confirmed before an account is used.
- You get an email when a passkey is added or your password changes.
- API keys are shown once, stored only as a hash, limited to the scopes you choose, and carry a checksum so leaked keys can be recognised.
- Agents connect over MCP with OAuth 2.1, so a person always signs in and approves the connection.
How we test it
We send test submissions containing a unique marker and check that it never appears in our database, logs or email, and that no account other than the recipient's can open it. The last check, on 4 October 2026, passed.
Where it runs
- The app runs on Cloudflare Workers. Cloudflare holds SOC 2 Type II and ISO 27001 certifications.
- Account and form data is in Neon Postgres, which holds SOC 2 Type II. Private submissions are never stored there.
- Wormhole itself has not had an independent audit yet.
Report a problem
If you find a security issue, email jacob@vwork.digital with the details and steps to reproduce it. Please give us a reasonable chance to fix it before telling anyone else, and do not access other people's data while testing. We will reply and keep you updated until it is fixed. Our security.txt has the same details.