قرطاسQirtas

سياسة الأمن

الإبلاغ عن ثغرة

إن وجدت ثغرة أمنية في قرطاس أو في موقعه، فنرجو إبلاغنا بسرية عبر البريد yousuf@namari8.com قبل نشرها، وإرفاق ما يلي:

نسعى إلى الرد بأسرع وقت، ونعلن عن الإصلاح بعد صدوره.

النطاق

الإصدارات المدعومة

يُصلَح أحدث إصدار منشور فقط.

ما نعلنه عن التشفير

سبورات التطبيق وصورها المصغّرة وصورها المضافة مشفّرة على الجهاز بـ AES-256-GCM، ومفتاحها في التخزين الآمن لنظام التشغيل. ملفات PDF الأصلية والتسجيلات الصوتية والملفات المصدَّرة ونسخ السحابة غير مشفّرة من جهة التطبيق.

Security Policy

Reporting a vulnerability

If you find a security vulnerability in Qirtas or its website, please report it privately to yousuf@namari8.com before disclosing it, and include:

We aim to respond as quickly as possible, and we announce the fix once it is released.

Scope

Supported versions

Only the latest published version is fixed.

What we state about encryption

Boards, their thumbnails and the images added to them are encrypted on the device with AES-256-GCM, with the key kept in the operating system's secure storage. Original PDF files, audio recordings, exported files and cloud copies are not encrypted by the app.