ordo

Security

Security Policy

Axolet welcomes responsible reports that help protect Ordo users, Ordo Cloud, and the open-source project.

Effective and last updated: September 18, 2026

Privacy Terms Security
Report vulnerabilities privately

Request a private security contact through GitHub. Include no vulnerability details, secrets, or personal data in the public request.

Request private contact

1. Scope

This policy covers the latest publicly available Ordo Android app, the latest version of the Ordo server source code, Ordo Cloud at api.ordo.axolet.com, and the Ordo website operated by Axolet.

Independent deployments, third-party websites opened or saved through Ordo, GitHub, Expo, email providers, and device operating systems are outside Axolet's direct control. Vulnerabilities in Ordo code remain in scope even when discovered while testing your own deployment.

2. What to include

A useful report includes:

  • the affected component, version, URL, and deployment type;
  • a clear description of the issue and its likely impact;
  • reproducible steps or a minimal proof of concept;
  • relevant logs, screenshots, or request samples with secrets and personal data removed; and
  • any suggested mitigation and a way to contact you.

3. Research rules

Act in good faith. Test only accounts, data, and systems you own or have explicit permission to test. Stop when you have confirmed the issue. Do not access, retain, alter, or disclose other users' data; degrade availability; send unsolicited messages; use social engineering; deploy malware; or demand payment as a condition of disclosure.

Use the minimum activity necessary to demonstrate impact. If you encounter personal data or secrets, stop testing, do not copy them, and describe the exposure in your private report.

4. Our response

Axolet will review good-faith reports, attempt to acknowledge them within a reasonable period, investigate reproducible issues, and prioritize remediation according to severity and affected users. Complex issues and coordinated releases may take longer. We may ask for additional information and will communicate material status changes when practicable.

Please allow Axolet a reasonable opportunity to investigate and remediate before public disclosure. We do not currently operate a paid bug-bounty program and cannot promise compensation.

5. Safe harbor

If you make a good-faith effort to follow this Policy, Axolet will not initiate legal action against you for accidental, limited violations directly resulting from your authorized security research. This safe harbor does not authorize violations of third-party rights or law and does not bind third parties.

6. Security measures

Ordo includes safeguards such as hashed account passwords, hashed server-side session tokens, expiring access credentials, session revocation, optional multi-factor authentication, encrypted storage of TOTP secrets, rate limits on selected sensitive operations, URL-fetching restrictions, sanitized reader content, and platform secure storage for mobile credentials.

These controls reduce risk but do not guarantee that Ordo is free from vulnerabilities. Security also depends on current software, device integrity, deployment configuration, transport encryption, access control, and operational practices.

7. Self-hosting responsibilities

Self-host operators are responsible for restricting network access, configuring HTTPS, protecting environment and secret files, selecting a trusted email provider, applying updates, monitoring the server, retaining and testing backups, setting an appropriate CORS allowlist, and controlling operating-system and database access.

Folder locks are an additional in-app access control; they are not a substitute for full-device or server-disk encryption.

8. Supported versions

Security fixes are made for the latest available Ordo app and server release unless Axolet explicitly states otherwise. Users and self-host operators should update promptly. Older releases and modified deployments may not receive fixes or support.

9. Contact

Use the contact-request link above for vulnerabilities. The public issue should say only that you need a private security channel. Do not publish exploit details, secrets, or personal data.

ordo — the app that keeps your life in order
GitHub AGPL-3.0 Privacy Terms Security
© 2026 Axolet