PRIMERDECK

Security

This policy covers the PrimerDeck mobile app (iOS and Android, package com.primerdeck.app) and its API on Cloudflare Workers (/app/v1/*). It is the coordinated vulnerability disclosure policy required by the EU Cyber Resilience Act (Regulation (EU) 2024/2847, Article 13(17)) and it is published as security.txt (RFC 9116) at /.well-known/security.txt on the API host.

Manufacturer: Nexus E-Com B.V., trading as PrimerDeck, the Netherlands.

Reporting a vulnerability

  • Email: security@primerdeck.com.
  • Preferred languages: English, Dutch.
  • Please include: affected version (Settings, "Version"), platform, steps to reproduce, impact.
  • Do not include personal data of other people, and do not test against accounts that are not yours. Automated scanning, denial of service and social engineering are out of scope.
  • We do not run a bug bounty. We credit reporters who want to be credited.

What we promise

Step Target
Acknowledge the report within 5 working days
First assessment (severity, affected versions) within 10 working days
Fix for a confirmed vulnerability within 90 days, sooner when actively exploited
Coordinated publication after the fix is available in both stores, with the reporter's agreement

We ask reporters not to publish before the fix is available or 90 days have passed, whichever comes first. We will not take legal action against good-faith research that follows this policy.

Actively exploited vulnerabilities and severe incidents

Under Article 14 of the Cyber Resilience Act (applies since 11 September 2026) we notify the ENISA single reporting platform (routed to the Dutch CSIRT, NCSC) of an actively exploited vulnerability or a severe incident: early warning within 24 hours of becoming aware, notification within 72 hours, final report within 14 days (vulnerability) or one month (incident).

Support period and updates

  • Security updates are free and are published through the App Store and Google Play.
  • Support period: at least five years from the first store release, as the Cyber Resilience Act requires; the current end date is published in the store listing once the app is released.
  • Users are asked to update when a release fixes a security issue; the API can raise the minimum supported version so that outdated builds stop before they can be abused.

Design choices that limit impact

  • No purchase path, no payment data, no ad or tracking SDKs.
  • Sign-in through Shopify's hosted login (OAuth 2.0 with PKCE); the app never sees passwords.
  • Tokens and the database key live in the Keychain or Keystore, this device only; the local database is encrypted (SQLCipher); files are protected by the OS data protection classes.
  • The API uses signed session tokens with a revocation list, per customer and per IP rate limits, and returns no personal data in logs.
  • Dependencies are pinned in lockfiles, install scripts are disabled, and an audit at level high runs before every release.
Editorial-grade researchSources cited where it mattersRead in one sittingInstant downloadEditorial-grade researchSources cited where it mattersRead in one sittingInstant download
FREE GUIDE · ONCE A MONTH

One short, useful guide.
Every month.

Delivered to your inbox. No fluff, no spam.

1 FREE GUIDE · ONCE A MONTH