Security
Security at Whist
Effective: August 8, 2026
Where things stand
Whist is a messenger built around privacy, and we describe its security the same way we build it: honestly. Today, conversations are encrypted at rest, and every conversation has a safety number you can verify in person.
End-to-end encryption is live: messages are sealed on-device with MLS (RFC 9420) and our servers only ever carry ciphertext. We label it “beta, unaudited” — the protocol library is independently audited, our integration’s third-party review is being commissioned, and the label comes off when that report is in hand. The full status of every security property lives in the security brief.
Reporting a vulnerability
Found something? We want to know — that’s not a nuisance, it’s a favor. Email [email protected] with [security] in the subject line.
Helpful details: what you found, where (URL, endpoint, or app surface), steps to reproduce, and what you think the impact is. We’ll acknowledge your report within a few days and keep you posted as we fix it.
Good-faith research
We welcome good-faith security research and won’t pursue legal action over it. In return, we ask the usual things: don’t access or modify data that isn’t yours, don’t degrade the service for others, and give us a reasonable window to fix an issue before disclosing it publicly.
Scope
The whistapp.com website today, and the Whist app and its backend once they ship. If you’re unsure whether something is in scope, email us anyway — worst case, we say thanks and point you somewhere better.
No bug bounty yet
We’re a small studio and don’t run a paid bounty program yet. What we can offer today: fast, human replies, credit for the find if you want it, and a fix. If that changes, this page changes.