Nordkastell
Apps Client Pricing Log in Early access
Apps Client Pricing Log in Early access

Security

How to report a security vulnerability in Snacka or the Nordkastell platform, and what you can expect from us when you do.

Last updated
26 September 2026
Operated by
H5 FörnyelsebyrÄ AB

Contents

  1. How to report
  2. What we do
  3. What this covers
  4. Testing in good faith
  5. Publishing
  6. The Cyber Resilience Act
  7. More

How to report

Email security@nordkastell.se, in English or Swedish. Please tell us:

  • what is affected: the app and its version, or the address of the page or service;
  • how to reproduce the problem, step by step;
  • what an attacker could do with it;
  • how we can reach you, and whether you would like to be named.

If you came across someone else's personal data, describe what you saw rather than sending it to us.

What we do

  • We confirm that we have your report, look into it and tell you what we find.
  • We keep you informed while we work on a fix, and tell you when it is out.
  • We share your report only with the people who need it to fix the problem, and your name with no one unless you agree.

What this covers

  • The Snacka apps for iPhone, Android, Windows, Mac and Linux.
  • The services they rely on: the Snacka server, sign-in to the workspace, the relay that delivers phone notifications, and the service that delivers desktop updates.
  • The other Nordkastell apps on workspace servers, like Alma, Tida and Tempa.
  • Our platform: nordkastell.se, account.nordkastell.se, admin.nordkastell.se and api.nordkastell.se.

Problems in services run by other companies, like Apple, Google, Expo or GitHub, belong with them, but tell us too if one affects us. Denial of service, spam, social engineering, physical attacks, and findings that need a device someone has already taken over are outside this policy.

Testing in good faith

  • Only test with accounts and workspaces that are yours, or that you have permission to test. Never test against another customer's workspace. The public playground is shared with other visitors, so do nothing there that gets in their way.
  • Do not access, change or delete more data than you need to show the problem. If you reach someone else's data, stop, do not keep it, and tell us.
  • Do not slow down or interrupt the service for others.
  • Give us time to fix the problem before you tell anyone else about it.

If you follow these rules, we see your research as done in good faith, and we will not take legal action against you or report you to the police for it.

Publishing

Please do not publish or share details of a vulnerability before a fix is available and we have agreed with you on when. Once it is fixed, you are welcome to write about it.

The Cyber Resilience Act

The Snacka apps are covered by the EU Cyber Resilience Act. It requires us to report a vulnerability that is being actively exploited, and a severe incident that affects the apps' security, to the authorities (in Sweden, CERT-SE) and to ENISA, the EU's cybersecurity agency, and to tell the people affected how to protect themselves. If your report concerns something like that, we may pass technical details on to them, but not your name unless you agree.

More

This policy is also published in machine-readable form at /.well-known/security.txt. How we handle personal data, including in a report, is described in our privacy policy.

© 2026 Nordkastell. All rights reserved.

Privacy policy | Terms of service | Support | Security | Delete account
English | Svenska