Skip to content

Security

Security and disclosure

How to report a vulnerability, what finding one pays, and what we commit to once you do.

Open source, and finding a flaw pays

PrivaMesh builds on well-studied primitives - X3DH, the Double Ratchet, AES-256-GCM, and ML-KEM-768 on iOS 26. The code that implements them is public for all three clients, so anyone can read exactly what it does rather than take a description on trust.

A flaw found in it is worth up to $500 through the bug bounty.

Reporting a vulnerability

Email privamesh@proton.me with security in the subject line.

  • Include the app version, your device model and your iOS version.
  • Include enough detail to reproduce the issue.
  • Never include your recovery phrase. We will never ask for it, for any reason, in any context.

What we commit to

  • Acknowledgement within 2 business days. If you do not hear back, assume the mail was lost and send it again.
  • A fix or a plan within 30 days for anything that lets someone read messages, impersonate an account, or link a user to their activity.
  • Credit if you want it, silence if you do not. We will not name you without asking.
  • No legal threats for good-faith research that does not target other people’s accounts or data.

Rewards

Confirmed findings are paid through the bug bounty program — up to $500 for a critical vulnerability, and payment happens on confirmation rather than on fix. The tiers, the scope and the known issues that do not qualify are all published there, because a program that quietly pays for its own documented gaps is not a program.

Supported versions

Security fixes go to the current App Store release. PrivaMesh requires iOS 26.5 or later and has shipped one major version, so there is no older branch to backport to. When that changes, the supported window will be stated here rather than implied.

What has been fixed

Nothing has been reported and fixed yet. Rather than leave this section out, it is here empty - a list that starts at zero and grows is more informative than a section that appears only once there is something flattering to put in it.

Scope

The iOS client, the on-chain protocol, and the fee worker described on the architecture page are all in scope. Third-party infrastructure - Solana itself, RPC providers, Apple - is not ours to fix, though we want to hear about it. For the boundaries of what the design protects, see the threat model and known limitations.

Frequently asked questions

How do I report a vulnerability?

Email privamesh@proton.me with "security" in the subject line. Include the app version, your device and iOS version, and enough detail to reproduce. We aim to acknowledge within 2 business days.

Is there a bug bounty?

Yes. Up to $500 for a critical finding, $200 high, $75 medium, $25 low, with severity defined by what the finding breaks in our threat model. Full tiers, scope and exclusions are on the bug bounty page.

Which versions get security fixes?

The current App Store release. Because PrivaMesh requires iOS 26.5 or later and has shipped a single major version, there is no older branch to backport to yet.

Keep reading