Qwing ships hybrid post-quantum end-to-end encryption, and its own protocol. If you find a flaw in it — in the cryptography, in the apps, in the server, or in anything that ships — we want to hear about it, and we will tell you what we are doing about it. This page is the public vulnerability-disclosure policy for Qwing (CODEARMORY). It is published at a stable URL (qwing.app/security.html) and is the policy referenced by qwing.app/.well-known/security.txt.
1. How to report
- Email security@qwing.app. This address reaches the maintainer directly.
- If you prefer not to identify yourself, say so and we will not ask. We do not need your name to fix something.
- Include what you can: affected component and version, what you did, what happened, and what you expected. A proof of concept helps and is welcome; a clear description is enough to start.
- Reports about a user's account or data (rather than a flaw in Qwing) are handled as support requests: write to support@qwing.app.
2. What we do, and when
These are commitments, not aspirations. Every report gets a human answer inside these windows.
| Within | What happens |
|---|---|
| 24 hours | We acknowledge your report. If it describes something exploitable, we start triage immediately and tell you what we have understood so far. |
| 72 hours | We send an assessment: whether it reproduces, our severity view, the affected releases, and the action plan with the dates we are working to. If we cannot reproduce it, we say so and ask for what we need. |
| Then | We keep you updated at every meaningful step — when a fix is written, when it ships, and when it is available to users. Critical and high-severity issues are fixed and released before we publish anything about them. |
| Publication | We publish an advisory once a fix is available, with your report credited under the name you choose (or anonymously). We ask you to hold publication until then, and we will not hold it longer than the fix takes. |
3. Cyber Resilience Act
Qwing is a product with digital elements placed on the EU market, so the manufacturer's obligations of Regulation (EU) 2024/2847 (the Cyber Resilience Act) apply to it, including coordinated vulnerability disclosure and reporting. In practice that means:
- This policy is the coordinated vulnerability disclosure policy: reports are received at the address above, handled on the timeline above, and the reporter is kept informed.
- For a vulnerability that is being actively exploited, our internal 24-hour step is an early warning to the EU single reporting platform, the 72-hour step is the notification with the assessment and any corrective measure available, and a final report follows within 14 days of the fix being available. The same reports are mirrored to the national CSIRT. Article 14 of the Regulation has applied since 11 September 2026.
- We do not contact a reporter's employer, platform provider or any third party about a report.
4. Safe harbour
If you report in good faith and follow this policy, we will not pursue legal action against you or ask anyone else to, and we will say publicly that your research was authorised. In return, we ask you to:
- test only against your own accounts and devices, or against accounts you have explicit permission to use;
- not access, modify or retain anyone else's data — if you reach data that is not yours, stop, and tell us what you saw without copying it;
- not degrade the service: no denial-of-service testing, no spam, no automated scanning that costs other users anything;
- give us the time in section 2 before publishing.
5. What is in scope
- The protocol and its implementation: the session and ratchet logic, envelope formats, key handling, and the shipped native libraries.
- The apps: Android and iOS, including the local storage, the lock and wipe paths, and the call stack.
- The server and its API: authentication, message relay, mailbox quotas, rate limits, the vault, and the push path.
- The web pages on qwing.app.
Out of scope: findings that need a rooted or jailbroken device or physical access to an unlocked phone (we describe those threats in the threat model instead); missing hardening headers on static pages with no user data; reports produced only by an automated scanner with no demonstrated impact; and third-party services we do not control (the app stores, APNs/FCM, coturn's upstream code).
6. Payment
There is no bug bounty. We are a small project and we would rather tell you that plainly than imply a reward we cannot pay. What we do give is the timeline above, a fix, credit if you want it, and an answer to every question you ask about what we did.
7. Advisories
Advisories and the status of every internal review are recorded in the repository's audit directory (this document set becomes public with the source). No independent third-party audit has been completed yet, and we say so wherever we describe the security of the product.