Security · Responsible disclosure

Found a weakness?
Tell us before anyone else.

We build a security product, so we take reports seriously and we treat the people who send them as allies. Report in good faith, give us a fair window to fix it, and we'll work it with you, no lawyers, no theatrics. This page is the deal we offer security researchers.

How to report

Send it straight to us.

One inbox, read by a human on the team. Encrypt the details if they're sensitive.

Email security@anadevyra.com. For anything you wouldn't put on a postcard, install the app, share your node ID in that same email, and we'll move the conversation into an end-to-end-encrypted thread before you share the real detail.

A good report includes: the affected build or version, clear steps to reproduce, what an attacker could actually achieve, and how we can reach you. Proof-of-concept is welcome; please keep it to your own accounts and your own devices.

What you get back

Our side of the deal.

Acknowledged in 48 hours
We confirm we've received your report within two business days, a real reply from a person, not an auto-responder that vanishes.
Kept in the loop
We tell you what we found, whether we could reproduce it, and where the fix stands. No black hole between "thanks" and silence.
Fix first, then disclose
We coordinate timing with you and ship the fix before public discussion. We won't sit on a serious issue, and we won't rush you out the door either.
Credit, if you want it
We're a small team ahead of launch, so there's no cash bounty program yet, but we'll credit you publicly with your blessing. Honest recognition over a hollow promise.
The rules

Scope and safe harbor.

Stay inside these lines and you're a researcher we want to hear from, not someone we have a problem with.

In scope

  • The WingPost Android app (the official APK)
  • The relay and API at api.anadevyra.com
  • This website, anadevyra.com

Out of scope

  • Volumetric denial-of-service and automated scanner noise
  • Social engineering of our team, or physical attacks
  • Third-party platforms we don't run (GitHub, mail and push providers)
  • Unrelated side projects that are not part of this app

Our safe harbor

  • Good-faith research that respects these rules will not be pursued legally
  • Don't access, modify, or keep data that isn't yours
  • Don't degrade the service for real users, give us a fair window to fix
"

A privacy product is only as honest as its willingness to be told it's wrong. If you take the time to find and report a flaw responsibly, you've made the app safer for everyone who uses it, and we won't forget that.

AnA Devyra Security