Security
Last updated: 2026-08-24. First publication.
Anchorwright builds iPhone and iPad apps. This page tells you how to report a security problem in one of them, or in this website, and what to expect after you do.
Reporting a vulnerability
Email security@anchorwright.com.
Tell us which app or page you were looking at, what you found, and the steps to reproduce. For an app, include the version number and your device model. A short working proof of concept helps far more than a long description of the theory.
Write in English. Every report reaches a person and gets read.
What happens next
Anchorwright is a one person company, and this page will not pretend otherwise.
We acknowledge your report by email. We do not publish a response time, because a deadline we miss is worse than no deadline at all. We will tell you what we decided, and whether a fix shipped. When we disagree with your assessment, we explain why rather than going quiet.
What we ask of you
Give us a fair chance to fix the problem before you publish anything about it.
Test against your own device and your own data. Do not read, change, or delete anything belonging to another person. Do not degrade the service for anyone else. Leave social engineering, physical access, and attacks on our suppliers out of scope entirely.
Good faith research
We will not pursue legal action over security research conducted in line with this page.
Scope
Every app Anchorwright publishes on the App Store, and this website.
Some things fall outside our reach. Reports produced by an automated scanner with no demonstrated impact, missing security headers with no working exploit, and defects in Apple’s own platform or in iCloud all belong somewhere else. Apple runs its own reporting channel for the last of those.
Rewards
We run no bug bounty and we pay nothing for reports.
When a report leads to a fix and you want the credit, we will name you here.