Security
We take the security of TapNomad seriously and appreciate researchers who report vulnerabilities responsibly. This page is the right channel; the machine-readable version lives at /.well-known/security.txt.
Reporting a vulnerability
Email security@rabotto.com with:
- a description of the issue and where it lives (app, API, website, offline packs),
- steps to reproduce, and
- your assessment of the impact.
Please report in English or Finnish.
Encrypting your report
For sensitive details you can encrypt your email with our PGP key:
/.well-known/pgp-key.asc (ed25519, fingerprint
E906 B4DD 020B 4343 724B B06D D62C A476 C4C1 73C7).
What to expect
- We acknowledge reports within 5 business days (TapNomad is built by a one-person company, so please bear with us).
- We will tell you what we found, what we are fixing and when, and let you know when the fix ships.
- With your permission we will credit you here once the issue is resolved. We do not currently run a paid bounty program.
Ground rules (safe harbor)
We will not pursue legal action for good-faith security research that:
- stays within your own accounts and data — TapNomad has no user accounts, so in practice: do not access, modify or delete data that is not yours,
- does not degrade the service for others (no volumetric denial-of-service testing; our rate limits are part of the system, hitting them once is fine, hammering them is not),
- does not use social engineering, phishing or physical attacks, and
- gives us reasonable time to fix the issue before public disclosure.
Scope
In scope: the TapNomad iOS app, api endpoints under our Supabase project, the tiles.tapnomad.app content service, and this website. Out of scope: third-party services we use (Apple, RevenueCat, Supabase, Cloudflare, Sentry) — report issues in those to the vendor, though we appreciate a heads-up if TapNomad’s use of them is misconfigured.