Security and disclosure
How your tasks are protected
Your task content is encrypted on your device before it is sent, with a key that only your devices, your Recovery Key and your passkeys can unlock. Our servers store the encrypted data, what is needed to sync it (record identifiers, sizes and times), and your account information, such as your email address and signed-in devices, which we can see. We cannot read your tasks, and we cannot recover them for you.
We are honest about the limits. The web app’s code is delivered by our server, so you are trusting us to deliver it unmodified; a compromised browser or extension can read what you see on screen. The privacy policy lists exactly what the server can see.
Reporting a vulnerability
If you believe you have found a security problem in Sahife, email security@sahife.app. Please include what you found, how to reproduce it and what an attacker could do with it. You don’t need to have a finished exploit.
- We acknowledge reports within 3 working days and keep you updated.
- We aim to fix serious problems within 30 days and agree a disclosure date with you; please give us that time before publishing.
- We credit reporters who want to be credited.
Safe harbour
We will not take legal action against research done in good faith that follows this policy:
- test only against your own accounts, or accounts whose owners agreed;
- never access, change or delete other people’s data — stop and report as soon as you could;
- no denial-of-service, spam, social engineering or physical attacks;
- keep the details private until the problem is fixed and we agreed a date.
In scope
The Sahife web app and API (sahife.app and its subdomains), the encryption and
sync design, and this website. Reports about missing best-practice headers without a real
impact, or about outdated browsers, are welcome but usually not treated as vulnerabilities.
Machine-readable contact details: /.well-known/security.txt.