Security
Careful at every boundary.
Sheet Zipper uses bounded package parsing, path validation, checksums, temporary-file isolation, and no-overwrite publication to reduce the risk of malformed or changing inputs.
Output integrity
- Optimization candidates are checked before publication.
- XLZ archives carry package and entry checksums.
- Restored workbooks are analyzed again before they appear at the selected destination.
- Source identity is rechecked during long-running work to detect replacement or modification.
Report a vulnerability
Send private reports to support@evernivo.com with the subject “Private security report”. Include the application version, operating system, error code, and a minimal synthetic reproduction.
Do not attach sensitive or proprietary workbooks to public GitHub issues.