Security & Responsible Disclosure

How to report a vulnerability in Tawhid
Last updated: 7 August 2026

Report to: info@tawhidapp.com with the subject line Security.

We acknowledge reports within 5 business days. Good-faith research is welcome and will not be met with legal action.

How to report

We take security seriously — Tawhid handles location data, and location data deserves care. If you have found a vulnerability, we want to hear about it.

Email info@tawhidapp.com with the subject line Security. A useful report includes:

  • The affected product — website, iOS app, or Android app — and the version;
  • Clear steps to reproduce, ideally with a proof of concept;
  • What an attacker could actually achieve, and roughly how hard it would be;
  • Any logs, requests, or screenshots that help us confirm it quickly.

Please report in English or Arabic if you can. A machine translation of a clear report is far better than no report.

A machine-readable copy of this policy is published at /.well-known/security.txt.

In scope

  • tawhidapp.com and its subdomains
  • The Tawhid iOS app
  • The Tawhid Android app

Vulnerability classes we especially care about: anything exposing user location or account data, authentication and authorisation flaws, remote code execution, injection, insecure data storage on device, exposed credentials or API keys, and issues in how we handle payment flows.

Out of scope

The following are not eligible and we would rather you did not spend time on them:

  • Denial of service, volumetric, or stress testing of any kind
  • Social engineering, phishing, or physical attacks against our team or users
  • Reports generated solely by an automated scanner with no demonstrated impact
  • Missing security headers or weak TLS configuration with no practical exploit
  • Issues requiring a rooted, jailbroken, or already fully compromised device
  • Vulnerabilities in third-party services we use — report those to the vendor
  • Self-XSS, clickjacking on pages with no sensitive action, or missing rate limits on non-sensitive endpoints

What to expect from us

  • Within 5 business days — we acknowledge your report.
  • Within 15 business days — we confirm whether we can reproduce it and give you our assessment.
  • Within 90 days — we aim to have a fix released, and will keep you updated if it takes longer.

We will tell you honestly if we decide not to fix something, and why. We will not argue a valid finding down to avoid acting on it.

What we ask of you

  • Give us a reasonable window to fix the issue before disclosing it publicly — 90 days is our default, and we are happy to agree something different.
  • Use only test accounts and your own data. Do not access, modify, or retain anyone else's information.
  • Stop as soon as you have confirmed a vulnerability exists. Do not pivot deeper to see how far you can get.
  • Do not degrade the service for other users — people rely on this app to pray on time.
  • Delete any data you incidentally obtained once you have reported it.

Safe harbour

If you make a good-faith effort to follow this policy, we will treat your research as authorised. We will not pursue or support legal action against you, and if a third party brings action against you for research that complied with this policy, we will make it known that your activity was authorised.

This does not extend to research that breaks the law independently, accesses other people's data beyond what is needed to prove an issue, or causes damage or disruption.

Recognition

We are a small company and do not currently run a paid bug bounty. What we can offer is a prompt, honest response, a real fix, and public credit on this page if you would like it — or your preferred anonymity if you would not.

Advice for users

Tawhid will never ask you for your password, payment card details, or government ID by email. We do not run giveaways. Anything you ever pay for in Tawhid is handled entirely by Google Play or the Apple App Store — we will never ask you to send money directly, by bank transfer, gift card, cryptocurrency, or a payment link. Treat any message that does as fraudulent.

Download the app only from the Google Play Store or the Apple App Store. If you receive a suspicious message claiming to be from Tawhid, forward it to info@tawhidapp.com.