Preview site. This site is a preview: the hosted download is not connected yet. The project itself is real.

Security

Safe by default, and easy to report

This example page explains how Pagkugi handles message content and how to report a security issue. The contact address below is a placeholder and will be replaced before launch.

Placeholder notice. The security contact shown here is an example. Replace it with the real reporting address before launch.

How Pagkugi handles message content

Pagkugi does not render message HTML inside the application. HTML is reduced to a safe, readable text representation instead of being handed to a browser engine.

Dangerous, interactive, embedded, hidden, and tracking-only content is removed. Safe visible text and approved links are kept, and remote resources are not fetched silently.

Message content is never executed and is never passed to a shell, so opening a message cannot run code.

Reporting a security issue

Send a description of the issue to security@pagkugi.com. Include the version of Pagkugi, the operating system, and the smallest reproduction you can make with synthetic data.

Please do not include personal mail, private keys, or passwords. If the issue is a rendering concern, describe the message shape rather than sending a real message.

Machine-readable contact

Security contacts are also published at /.well-known/security.txt, using example fields for the same placeholder contact.