سياسة الأمن
الإبلاغ عن ثغرة
إن وجدت ثغرة أمنية في قرطاس أو في موقعه، فنرجو إبلاغنا بسرية عبر البريد yousuf@namari8.com قبل نشرها، وإرفاق ما يلي:
- وصف الثغرة وأثرها.
- خطوات إعادة إنتاجها، واسم النظام وإصدار التطبيق.
- ما تراه مناسباً من لقطات أو ملفات.
نسعى إلى الرد بأسرع وقت، ونعلن عن الإصلاح بعد صدوره.
النطاق
- ضمن النطاق: تطبيقا Android وWindows، وموقع qirtas.namari8.com، ووسيط تسجيل الدخول إلى Google في نسخة Windows.
- خارج النطاق: الهندسة الاجتماعية، وهجمات حجب الخدمة، والثغرات في خدمات الغير (Google وMicrosoft وCloudflare وNetlify).
الإصدارات المدعومة
يُصلَح أحدث إصدار منشور فقط.
ما نعلنه عن التشفير
سبورات التطبيق وصورها المصغّرة وصورها المضافة مشفّرة على الجهاز بـ AES-256-GCM، ومفتاحها في التخزين الآمن لنظام التشغيل. ملفات PDF الأصلية والتسجيلات الصوتية والملفات المصدَّرة ونسخ السحابة غير مشفّرة من جهة التطبيق.
Security Policy
Reporting a vulnerability
If you find a security vulnerability in Qirtas or its website, please report it privately to yousuf@namari8.com before disclosing it, and include:
- A description of the vulnerability and its impact.
- Steps to reproduce it, the operating system and the app version.
- Any screenshots or files you consider useful.
We aim to respond as quickly as possible, and we announce the fix once it is released.
Scope
- In scope: the Android and Windows apps, the website qirtas.namari8.com, and the Google sign-in relay of the Windows version.
- Out of scope: social engineering, denial-of-service attacks, and vulnerabilities in third-party services (Google, Microsoft, Cloudflare, Netlify).
Supported versions
Only the latest published version is fixed.
What we state about encryption
Boards, their thumbnails and the images added to them are encrypted on the device with AES-256-GCM, with the key kept in the operating system's secure storage. Original PDF files, audio recordings, exported files and cloud copies are not encrypted by the app.