Security

How NotepadMD protects your data — from local encryption to signed releases and secure cloud infrastructure.

NotepadMD is built with security at every layer — from local data encryption to signed releases and secure cloud infrastructure.

Local Data Encryption

NotepadMD encrypts your local session database using AES encryption provided by LiteDB. The encryption key is generated per-user and protected by the Windows Data Protection API (DPAPI), binding it to your Windows user account.

  • Encryption: AES encryption via LiteDB's built-in encryption engine
  • Key storage: A 256-bit random key is generated on first launch and stored encrypted with DPAPI (CurrentUser scope) at %LocalAppData%/NotepadMD/notepadmd.key
  • User-bound: The encryption key is tied to your Windows login — only your account can decrypt the database
  • No recovery by design: If the key file is lost or the Windows profile is corrupted, the database cannot be recovered. Your original Markdown files on disk are not affected

This ensures that session data (open tabs, draft content, settings) is protected at rest, even if another user or process accesses the database file.

Closed Source Codebase

The NotepadMD source code is hosted in private repositories with restricted access. Only authorised developers can view or modify the codebase. All changes require pull request review before merge.

Signed Executables

All NotepadMD releases are digitally signed using Azure Trusted Signing, providing:

  • Code signing certificates issued by a Microsoft-trusted certificate authority
  • Tamper detection — Windows will warn users if a binary has been modified after signing
  • Publisher verification — users can verify the publisher identity before installation

NotepadMD is also distributed through the Microsoft Store, which applies additional integrity validation and sandboxing.

Build Pipeline

NotepadMD is built on privately hosted build servers using Azure Pipelines. The build pipeline:

  • Runs on isolated, ephemeral agents
  • Uses pinned dependency versions via NuGet.Config and lock files
  • Produces reproducible builds from tagged commits
  • Publishes signed artefacts directly to distribution channels

No third-party CI/CD services have access to signing keys or production credentials.

OWASP Compliance

We conduct regular OWASP Top 10 security audits of all public-facing API endpoints. Our most recent audit confirmed compliance across all 10 categories, with our authentication, injection prevention, and cryptographic implementations meeting or exceeding recommended standards.

Key areas addressed:

  • Injection prevention: Parameterised queries (Entity Framework Core) across all database operations
  • Broken authentication: HMAC-SHA256 request signing with nonce replay protection
  • Cryptographic failures: TLS 1.2+ enforced on all endpoints; DPAPI for local key storage
  • Security misconfiguration: Minimal attack surface with firewalled databases and Key Vault secret management
  • Vulnerable components: Automated dependency scanning with regular updates

Licensing Security

The NotepadMD licensing infrastructure is designed with defence in depth:

  • Firewalled database: The licensing SQL database is accessible only from the API application service — no public endpoint
  • HMAC-SHA256 authentication: Authenticated API requests are signed using per-device HMAC secrets, preventing tampering and replay
  • Nonce replay protection: Each authenticated request includes a unique nonce; replayed requests are rejected
  • Key Vault secrets: All sensitive configuration (database credentials, signing keys, API keys) is stored in Azure Key Vault
  • TLS 1.2+: All API communication is encrypted in transit
  • Rate limiting: API endpoints are rate-limited to prevent abuse

Payment Security

NotepadMD uses Paddle as our Merchant of Record for all payment processing. This means:

  • NotepadMD never handles payment card data — all payment processing is managed by Paddle
  • PCI DSS compliance is maintained by Paddle as the payment processor
  • Secure webhooks from Paddle are validated before processing

Data Minimisation

NotepadMD collects only the minimum data necessary to operate:

  • No telemetry by default: The desktop application does not phone home or collect usage analytics, with the exception of a single "first install" counter call that does not post any additional information back to the server.
  • Licensing data: Limited to licence key, device fingerprint, and activation status — no personal files or content
  • No cloud sync: Your Markdown files stay on your machine. NotepadMD does not upload, sync, or backup your documents to any server

Vulnerability Disclosure

If you discover a security vulnerability in NotepadMD, please report it responsibly:

  • Email: [email protected]
  • Acknowledgment: We will acknowledge receipt within 48 hours
  • Resolution: We aim to investigate and resolve confirmed vulnerabilities promptly
  • Disclosure: We will coordinate disclosure timelines with the reporter

Please do not open public GitHub issues for security vulnerabilities.