NaviVolta is made by one person. If you have found a security problem — in the app, on the site, or in the way data is kept — we would rather hear it from you than learn it the hard way.
Write to navivolta.app@gmail.com with a subject starting with SECURITY. Describe what you found, how to reproduce it and what you think could happen. Screenshots and recordings help — blur other people's data first.
The same address is in /.well-known/security.txt (RFC 9116).
There is no bug bounty yet: the project is one person with no revenue. We say so rather than stay silent about it.
Out of scope: the systems of Google, Mapbox, Cloudflare and the charging operators — report those to them. If we misconfigured something of theirs, that is ours and we want to hear it.
Say so in the first sentence. An actively exploited vulnerability has to be reported under the EU Cyber Resilience Act (Regulation (EU) 2024/2847) on short deadlines, so we need it now, not at the end of the week.
The list of libraries in the app (SBOM) and their check against the known-vulnerability database are run regularly; that check is part of our test gate and fails if it is more than 30 days old or if an unchecked library went in.
The app is an early Alpha. That is no excuse for a security hole — it only means a fix sometimes ships with the next version rather than the same day.