Postal Pigeon
Features Security Web App Pricing Get the app
Back to Postal Pigeon

Security

Security Disclosure

Last updated: July 29, 2026

Our commitment

Postal Pigeon's entire premise rests on the encryption holding up under scrutiny — so we'd rather find out about a flaw from a careful researcher than after the fact. This page explains how our encryption is built, what's in scope for security research, and how to report a vulnerability so we can fix it quickly and credit you for finding it.

Encryption architecture

Postal Pigeon combines a Signal-style double-ratchet key exchange with AES-256-GCM payload encryption and per-device key rotation:

  • X3DH-style key agreement, providing forward and future secrecy between sessions;
  • AES-256-GCM authenticated encryption for message and file payloads;
  • Per-conversation ephemeral keys, rotated automatically as a conversation continues;
  • Keys generated and stored in the macOS Secure Enclave whenever available, and never transmitted off the device in any form;
  • Zero-knowledge relay infrastructure — our servers only ever handle ciphertext in transit and hold no decryption keys;
  • Permanent, automatic deletion of a conversation and its keys once the last participant leaves.

Our protocol specification and client source are published for independent audit, because "trust us" shouldn't be the only option you have.

Reporting a vulnerability

If you believe you've found a security vulnerability in Postal Pigeon, please report it privately to security@postalpigeon.app rather than filing a public issue or disclosing it on social media. Please include:

  • A description of the vulnerability and its potential impact;
  • Step-by-step instructions to reproduce it;
  • The app version, macOS version, and hardware architecture you tested on;
  • Any proof-of-concept code or screenshots that help us confirm the issue.

If you'd like to encrypt your report, request our current PGP key at the address above before sending sensitive details.

Scope

In scope: the Postal Pigeon macOS application, our relay and account infrastructure, and this website.

Out of scope: third-party services we integrate with (e.g. the payment processor) — please report those directly to the provider; denial-of-service testing against our infrastructure; social engineering of our staff or users; and physical attacks against a device you do not own.

What you can expect from us

  • We'll acknowledge your report within 3 business days.
  • We'll investigate and provide an initial assessment of severity and scope within 10 business days.
  • We'll keep you informed as we work toward a fix, and let you know when it has shipped.
  • With your permission, we'll publicly credit you for the discovery once a fix is released.

Safe harbor

We will not pursue legal action against researchers who discover and report vulnerabilities in good faith, provided they:

  • Make a genuine effort to avoid privacy violations, data destruction, and service disruption;
  • Only interact with accounts and data they own or have explicit permission to test;
  • Give us a reasonable opportunity to investigate and remediate before any public disclosure;
  • Do not exploit a vulnerability beyond what's necessary to demonstrate it.

Recognition

We don't currently run a paid bug bounty program, but we maintain a public thank-you list for researchers who report valid, previously unknown vulnerabilities and wish to be credited. Let us know in your report if you'd like to be listed (and how you'd like your name or handle to appear).

This page is a general-purpose draft. Set up the security@ mailbox and PGP key referenced above, and adjust the response-time commitments to whatever your team can realistically support before publishing.
Postal Pigeon

Encrypted by default. Stored nowhere. Gone when you're done.

Product

Features Security Web App Pricing Download

Company

About Blog Careers

Legal

Privacy Policy Terms of Service Security Disclosures

© 2026 Postal Pigeon. All rights reserved.

Made for macOS.