NotepadMD is built with security at every layer — from local data encryption to signed releases and secure cloud infrastructure.
Local Data Encryption
NotepadMD encrypts your local session database using AES encryption provided by LiteDB. The encryption key is generated per-user and protected by the Windows Data Protection API (DPAPI), binding it to your Windows user account.
- Encryption: AES encryption via LiteDB's built-in encryption engine
- Key storage: A 256-bit random key is generated on first launch and stored encrypted with DPAPI (
CurrentUserscope) at%LocalAppData%/NotepadMD/notepadmd.key - User-bound: The encryption key is tied to your Windows login — only your account can decrypt the database
- No recovery by design: If the key file is lost or the Windows profile is corrupted, the database cannot be recovered. Your original Markdown files on disk are not affected
This ensures that session data (open tabs, draft content, settings) is protected at rest, even if another user or process accesses the database file.
Closed Source Codebase
The NotepadMD source code is hosted in private repositories with restricted access. Only authorised developers can view or modify the codebase. All changes require pull request review before merge.
Signed Executables
All NotepadMD releases are digitally signed using Azure Trusted Signing, providing:
- Code signing certificates issued by a Microsoft-trusted certificate authority
- Tamper detection — Windows will warn users if a binary has been modified after signing
- Publisher verification — users can verify the publisher identity before installation
NotepadMD is also distributed through the Microsoft Store, which applies additional integrity validation and sandboxing.
Build Pipeline
NotepadMD is built on privately hosted build servers using Azure Pipelines. The build pipeline:
- Runs on isolated, ephemeral agents
- Uses pinned dependency versions via
NuGet.Configand lock files - Produces reproducible builds from tagged commits
- Publishes signed artefacts directly to distribution channels
No third-party CI/CD services have access to signing keys or production credentials.
OWASP Compliance
We conduct regular OWASP Top 10 security audits of all public-facing API endpoints. Our most recent audit confirmed compliance across all 10 categories, with our authentication, injection prevention, and cryptographic implementations meeting or exceeding recommended standards.
Key areas addressed:
- Injection prevention: Parameterised queries (Entity Framework Core) across all database operations
- Broken authentication: HMAC-SHA256 request signing with nonce replay protection
- Cryptographic failures: TLS 1.2+ enforced on all endpoints; DPAPI for local key storage
- Security misconfiguration: Minimal attack surface with firewalled databases and Key Vault secret management
- Vulnerable components: Automated dependency scanning with regular updates
Licensing Security
The NotepadMD licensing infrastructure is designed with defence in depth:
- Firewalled database: The licensing SQL database is accessible only from the API application service — no public endpoint
- HMAC-SHA256 authentication: Authenticated API requests are signed using per-device HMAC secrets, preventing tampering and replay
- Nonce replay protection: Each authenticated request includes a unique nonce; replayed requests are rejected
- Key Vault secrets: All sensitive configuration (database credentials, signing keys, API keys) is stored in Azure Key Vault
- TLS 1.2+: All API communication is encrypted in transit
- Rate limiting: API endpoints are rate-limited to prevent abuse
Payment Security
NotepadMD uses Paddle as our Merchant of Record for all payment processing. This means:
- NotepadMD never handles payment card data — all payment processing is managed by Paddle
- PCI DSS compliance is maintained by Paddle as the payment processor
- Secure webhooks from Paddle are validated before processing
Data Minimisation
NotepadMD collects only the minimum data necessary to operate:
- No telemetry by default: The desktop application does not phone home or collect usage analytics, with the exception of a single "first install" counter call that does not post any additional information back to the server.
- Licensing data: Limited to licence key, device fingerprint, and activation status — no personal files or content
- No cloud sync: Your Markdown files stay on your machine. NotepadMD does not upload, sync, or backup your documents to any server
Vulnerability Disclosure
If you discover a security vulnerability in NotepadMD, please report it responsibly:
- Email: [email protected]
- Acknowledgment: We will acknowledge receipt within 48 hours
- Resolution: We aim to investigate and resolve confirmed vulnerabilities promptly
- Disclosure: We will coordinate disclosure timelines with the reporter
Please do not open public GitHub issues for security vulnerabilities.