Email [email protected]. We reply within 3 working days and tell you what we think within 10 working days.
What to send
Which app and version, the device and iOS version you saw it on, what you found, and how to reproduce it. If it is too sensitive to put in an email, say so first and we will find another way to take it.
What we do
We confirm we have it, tell you whether we could reproduce it and how serious we think it is, then fix it and let you know when the update is out. We will credit you when it ships unless you would rather we did not. There is no paid bounty — we would rather promise a fast, honest reply we can actually deliver.
We ask you to give us a chance to fix the problem before you publish it, to test only against your own device and your own data, and not to disrupt anything. If you do that, we will treat your research as authorised and we will not pursue you for it.
What is not ours to fix
Bugs in iOS itself, or in Apple's frameworks and services, go to Apple Product Security. We are also not the right people for scanner output with no demonstrated impact, or for findings that only work on a jailbroken device.
How updates reach you
Security fixes ship as ordinary App Store updates, free, to everyone on a supported version. Turn on automatic updates in Settings → App Store and you will get them without doing anything. We will never ask you to install our software from anywhere else.
Our apps keep your data on your device rather than on our servers, so deleting an app removes what it stored. Each app's privacy policy says exactly what that app holds.
Contact
[email protected] · also published in
security.txt
Stationify Oy, Helsinki, Finland · Y-tunnus
3608699-3