Security & Vulnerability Disclosure

Machine-readable version: /.well-known/security.txt (RFC 9116)

Reporting a vulnerability

If you believe you have found a security vulnerability in the Resift app or this website, please email security@tryresift.com with:

What to expect

Please practice coordinated disclosure: give us a reasonable window to ship a fix before publishing details. We will not take legal action against good-faith research that respects user data and does not disrupt the service.

Scope

The Resift iOS/Android apps and the websites tryresift.com and resift.app. Note that Resift is local-first — it operates no backend, which considerably limits the remote attack surface.

Security updates

Security fixes are distributed through App Store / Play Store updates and are flagged in the changelog. Our vulnerability-handling process and declared support period are maintained as part of our EU Cyber Resilience Act preparation.