We build a security product, so we take reports seriously and we treat the people who send them as allies. Report in good faith, give us a fair window to fix it, and we'll work it with you, no lawyers, no theatrics. This page is the deal we offer security researchers.
One inbox, read by a human on the team. Encrypt the details if they're sensitive.
Email security@anadevyra.com.
For anything you wouldn't put on a postcard, install the app, share your node ID in that
same email, and we'll move the conversation into an end-to-end-encrypted thread before you
share the real detail.
A good report includes: the affected build or version, clear steps to
reproduce, what an attacker could actually achieve, and how we can reach you. Proof-of-concept
is welcome; please keep it to your own accounts and your own devices.
Stay inside these lines and you're a researcher we want to hear from, not someone we have a problem with.
A privacy product is only as honest as its willingness to be told it's wrong. If you take the time to find and report a flaw responsibly, you've made the app safer for everyone who uses it, and we won't forget that.