Contact
Three ways in.
Each path has a stated response window. Vulnerability reports go to the security address, not to licensing.
Security
Report a vulnerability or plan a security review.
Coordinated disclosure for the SDK, and the evidence an enterprise reviewer asks for: protocol profile, threat model, boundaries, dependency posture, and audit status. The SDK is reviewed continuously by adversarial AI agents; it is not audited by any independent firm.
security@open-e2ee.devDo not include message plaintext, private keys, or customer data in a report. A reproduction against a test identity is enough.
Enterprise evaluation
Scope an Enterprise or OEM agreement.
Negotiated portfolio, redistribution, OEM, security, support, and service-level terms.
- Portfolio or OEM scope
- Redistribution terms
- Security review and SLA
- MSA and signed order form
Licensing
Scope a Growth license, or ask about AGPLv3.
Commercial rights with configurable product scope, implementation support, and services.
- Configurable product scope
- Priority updates
- Integration support
- Quote and signed order form
Have these ready
- Legal entity and the named covered products
- Runtimes the product ships on: Expo, React Native, browser, Node
- Storage, relay, and object-store adapters in use
- Portfolio use, redistribution, or OEM scope
- Security-review, SLA, and support requirements
Audit status, what this console stores, the subprocessor list, and the documents available on request are answered on the trust page.