← Expireless

Security Policy

Last updated: August 22, 2026

Expireless is a household food inventory and expiry tracking product: two mobile applications (iOS and Android) and the backend they require at api.expireless.app. This policy covers all three.

It is published in satisfaction of the coordinated vulnerability disclosure requirement in Annex I, Part II of Regulation (EU) 2024/2847 (the Cyber Resilience Act).

Reporting a vulnerability

Email [email protected] with SECURITY in the subject line.

This is currently the product's general contact address rather than a dedicated security mailbox. It is used here because it demonstrably reaches us — a freshly invented address that bounced would be worse than none. Mail marked SECURITY is triaged as a security report, not as an ordinary support ticket.

Please include, as far as you can:

If you believe the issue is being actively exploited, say so in the first line. That changes our obligations and our timeline, and we need to know immediately.

What to expect

Expireless is made by a sole proprietorship, not by a security team on rotation. These are honest targets rather than a guaranteed service level, and we would rather state modest ones we meet than ambitious ones we do not.

Disclosure

We will agree a disclosure timeline with you rather than impose one. Our default is that you publish once a fix is available to users, and we will credit you unless you prefer otherwise. Where a released version fixed a vulnerability, we say so in the release notes for that version.

Scope

In scope:

Out of scope, because they are not ours to fix — please report these to the operator concerned:

Safe harbour

If you act in good faith to investigate and report a vulnerability under this policy, we will not pursue legal action against you. Please do not access, modify or delete data belonging to anyone but yourself, do not degrade the service for other users, and do not use a finding for anything beyond demonstrating it.

Support period

The product's supported period runs until 1 July 2031. Reports against versions released within that window are in scope.

security.txt