Security Policy
Last updated: August 22, 2026
Expireless is a household food inventory and expiry tracking product: two mobile applications (iOS and Android) and the backend they require at api.expireless.app. This policy covers all three.
It is published in satisfaction of the coordinated vulnerability disclosure requirement in Annex I, Part II of Regulation (EU) 2024/2847 (the Cyber Resilience Act).
Reporting a vulnerability
Email [email protected] with SECURITY in the subject line.
This is currently the product's general contact address rather than a dedicated security mailbox. It is used here because it demonstrably reaches us — a freshly invented address that bounced would be worse than none. Mail marked SECURITY is triaged as a security report, not as an ordinary support ticket.
Please include, as far as you can:
- what the issue is and which part it affects — iOS app, Android app, or backend
- the version: iOS build number, Android versionCode, or the date and time of a request to the API
- steps to reproduce, or a proof of concept
- what an attacker could actually do with it
If you believe the issue is being actively exploited, say so in the first line. That changes our obligations and our timeline, and we need to know immediately.
What to expect
- Acknowledgement of your report — 3 working days
- Initial assessment, with our view of severity — 10 working days
- Fix or documented mitigation — depends on severity; we will tell you the plan
Expireless is made by a sole proprietorship, not by a security team on rotation. These are honest targets rather than a guaranteed service level, and we would rather state modest ones we meet than ambitious ones we do not.
Disclosure
We will agree a disclosure timeline with you rather than impose one. Our default is that you publish once a fix is available to users, and we will credit you unless you prefer otherwise. Where a released version fixed a vulnerability, we say so in the release notes for that version.
Scope
In scope:
- the iOS application (
com.mikllabs.expireless) - the Android application (
com.miklabs.foodgem) - the backend API at
api.expireless.app - the web properties at
expireless.app
Out of scope, because they are not ours to fix — please report these to the operator concerned:
- Google Gemini, OpenAI, Telegram, Sentry, Apple's App Store, Google Play
- findings that require a rooted, jailbroken or otherwise compromised device, where the platform's own security model is already defeated
- absence of certificate pinning and absence of code obfuscation — both are known, documented decisions rather than oversights: obfuscation is not a security control, and the API enforces authorisation server-side regardless of how readable the client is
- reports generated solely by a scanner, with no demonstrated impact on this product
Safe harbour
If you act in good faith to investigate and report a vulnerability under this policy, we will not pursue legal action against you. Please do not access, modify or delete data belonging to anyone but yourself, do not degrade the service for other users, and do not use a finding for anything beyond demonstrating it.
Support period
The product's supported period runs until 1 July 2031. Reports against versions released within that window are in scope.