Challapp
Back

Vulnerability reporting

Found a security issue in Challapp? Thank you for telling us. Here is how, and what we will do.

Version 1.0, 12 September 2026. Coordinated vulnerability disclosure policy under EU Regulation 2024/2847 (CRA).

Where to report

Write to security@challapp.cz. Machine-readable details are at challapp.cz/.well-known/security.txt. Describe what you found, how to reproduce it and the impact. If you can, include the app and iOS version.

What we do

  • Acknowledge receipt within 2 business days.
  • Within 10 business days tell you whether it is a vulnerability and how severe.
  • Ship a fix as soon as possible; critical issues first. Security updates are always free, via the App Store.
  • If the vulnerability is actively exploited, we report it under the CRA to the national CSIRT (NÚKIB) and ENISA within the statutory deadlines.
  • After the fix ships, we credit you if you wish.

Coordinated disclosure

Please allow 90 days from your report before publishing, or until the fix is released, whichever comes first. If it takes longer, we will agree on a date.

Do not test on other people's accounts or data, do not run denial-of-service, and do not extract more data than needed for proof. Within these bounds we will not pursue legal action over a report.

Support period

We will maintain the security of Challapp until at least the end of 2031, five years from release. Should that change, we will announce it in the app and here at least 12 months ahead.