Reporting a vulnerability
How to report a security problem in FOLD and what happens next.
If you find a security problem in FOLD, please tell us before you publish it, so we can fix it for everyone first.
Where to report
Write to security@datargo.com. We read reports in English and German.
If you want to encrypt your report, ask for our OpenPGP key first; we send it on request.
What helps us
- The FOLD version and platform (Mac, iPhone or iPad) and the operating system version.
- The steps to reproduce the problem, ideally with a sample message or a minimal test case.
- What an attacker could achieve, and under which conditions.
- Whether and when you plan to publish.
Please test only against your own accounts, devices and servers, and do not access other people’s data.
What happens next
We confirm receipt within 72 hours, assess the report and credit you when the fix ships.
FOLD does not run a paid bug bounty program.