Security
Safe by default, and easy to report
This example page explains how Pagkugi handles message content and how to report a security issue. The contact address below is a placeholder and will be replaced before launch.
Placeholder notice. The security contact shown here is an example. Replace it with the real reporting address before launch.
How Pagkugi handles message content
Pagkugi does not render message HTML inside the application. HTML is reduced to a safe, readable text representation instead of being handed to a browser engine.
Dangerous, interactive, embedded, hidden, and tracking-only content is removed. Safe visible text and approved links are kept, and remote resources are not fetched silently.
Message content is never executed and is never passed to a shell, so opening a message cannot run code.
Reporting a security issue
Send a description of the issue to security@pagkugi.com. Include the version of Pagkugi, the operating system, and the smallest reproduction you can make with synthetic data.
Please do not include personal mail, private keys, or passwords. If the issue is a rendering concern, describe the message shape rather than sending a real message.
Machine-readable contact
Security contacts are also published at /.well-known/security.txt, using example fields for the same placeholder contact.