Monkly
Security

Report a vulnerability

If you notice something in Monkly that puts other people at risk, tell us. We take every report seriously and we reply.

1

How to report

Write to security@monkly.app. Describe as precisely as you can what you found and how to reproduce it: the affected address or screen, the steps to get there, and what happens that should not happen.

Please use your own account for testing. Do not access other people data, do not change or delete anything that is not yours, and do not download data belonging to others. If you accidentally see someone else data while testing, stop and say so in your report.

This page and the file /.well-known/security.txt describe the same route. Both apply to monkly.app and app.monkly.app.

2

What we promise

We confirm receipt within 72 hours and follow up with a first assessment. Once the issue is fixed, we let you know.

Anyone who reports a vulnerability in good faith and follows the rules above has nothing to fear from us: we will not take legal action.

On request we credit you once the issue is fixed. There is no money behind this, we do not run a bug bounty programme.

3

When it is serious

For a vulnerability that is being actively exploited, or a severe security incident, we additionally report to the competent authorities as required by the EU Cyber Resilience Act.

We inform affected users as soon as we know what happened and what to do about it. We do not wait for the final report.

4

What does not belong here

Automated scanner output without a demonstrable impact, missing security headers without a concrete attack, and anything that only works with physical access to an unlocked device are not treated as vulnerabilities.

Questions about your account, subscriptions or how to use the app do not belong here. Use the regular support inside the app for those.

Found a vulnerability?
Write to us directly. We confirm receipt within 72 hours.
security@monkly.app