Security
Security Disclosure
Last updated: July 29, 2026
Postal Pigeon's entire premise rests on the encryption holding up under scrutiny — so we'd rather find out about a flaw from a careful researcher than after the fact. This page explains how our encryption is built, what's in scope for security research, and how to report a vulnerability so we can fix it quickly and credit you for finding it.
Postal Pigeon combines a Signal-style double-ratchet key exchange with AES-256-GCM payload encryption and per-device key rotation:
Our protocol specification and client source are published for independent audit, because "trust us" shouldn't be the only option you have.
If you believe you've found a security vulnerability in Postal Pigeon, please report it privately to security@postalpigeon.app rather than filing a public issue or disclosing it on social media. Please include:
If you'd like to encrypt your report, request our current PGP key at the address above before sending sensitive details.
In scope: the Postal Pigeon macOS application, our relay and account infrastructure, and this website.
Out of scope: third-party services we integrate with (e.g. the payment processor) — please report those directly to the provider; denial-of-service testing against our infrastructure; social engineering of our staff or users; and physical attacks against a device you do not own.
We will not pursue legal action against researchers who discover and report vulnerabilities in good faith, provided they:
We don't currently run a paid bug bounty program, but we maintain a public thank-you list for researchers who report valid, previously unknown vulnerabilities and wish to be credited. Let us know in your report if you'd like to be listed (and how you'd like your name or handle to appear).