If you find a security flaw, report it to us.
Our coordinated vulnerability disclosure policy: how to report, how we handle each report and the rules of conduct we ask you to follow during research.
Last updated: 4 October 2026
Vulnerability reports. For any other matter, write to support@soulmovement.app.
Scope
This policy covers the Soul iPhone app, its Apple Watch app, its widgets and the Soul API they use.
We also accept reports concerning this website, soulmovement.app.
Outside the scope of this policy:
- Apple's and our providers' own systems. If the vulnerability is in one of them, report it to them directly.
- Denial of service.
- Social engineering, against us or against people who use Soul, and physical attacks.
- Reports from automated scanners without a demonstrated impact.
Reporting procedure
Write to security@soulmovement.app and state:
- what you have identified and what it affects;
- how to reproduce it, step by step;
- the app version, shown in Profile › Settings, in the Version row.
Screenshots are helpful. A complete exploit is not required: it is sufficient that the vulnerability can be reproduced.
You may write to us in English or Spanish.
We do not publish a PGP key. If you need to send us encrypted information, request this in a first email without details and we will agree an appropriate method.
Response times
We commit to response times that we can meet.
Working days are calculated according to the Spanish calendar.
- Confirmation
- Within 5 working days we confirm receipt of your report.
- Assessment
- Within 10 working days we provide an initial assessment: whether we have been able to reproduce the vulnerability and how serious it is.
- Follow-up
- At least every 30 days we inform you of the status of the remediation, until it is resolved.
Rules of conduct during research
- Use your own account or test accounts that you created.
- Do not access, modify or retain other people's data. If you gain access to any, stop the test, inform us and delete the data.
- Do not carry out any action that degrades the service for other users or create accounts in bulk with automated tools.
- Do not make the vulnerability public until we have agreed a date (see below).
If you are unsure whether an action complies with these rules, consult us before carrying it out.
Good-faith research
If you act in accordance with these rules, we will not take legal action against you.
Nor will we file a complaint about your research, and we will consider it authorised by us.
This commitment binds only Soul. We cannot bind third parties, such as Apple or our providers, or public prosecutors.
Public disclosure
The date is agreed with you. By default, we publish an advisory on this website once the fix is available to people who use Soul, with your name if you wish it to appear.
If we cannot fix it, we inform you and agree with you what is published.
Authorities
If a vulnerability is being actively exploited, the law requires us to notify it to INCIBE-CERT and ENISA (Regulation (EU) 2024/2847, Article 14).
You may also report it to INCIBE-CERT, which coordinates vulnerability disclosure in Spain, instead of us or in addition to us.
No monetary reward
We do not pay rewards. We thank you and, if you wish, name you in the advisory.
Soul was started by someone who works in security, and it has been built with that care from day one. If you see something we missed, we want to know.
DaniCybersecurity Engineer · Cloud & App Architect