Security#

Vikunja recognizes the importance of excellent security practices. While we are a small team focused on providing efficient task and project organization, we work hard to ensure top-notch security for all our users. We understand that project management often involves sensitive information, and we are committed to protecting your data with the utmost care.

This document covers our security practices and policies. If you are interested in the data we collect and store, please refer to our privacy policy.

General practices#

Vikunja Cloud Hosting#

All parts of Vikunja Cloud and this website are hosted at Hetzner in Germany and Finland. Their data centers are kept secure through multiple layers of physical, network and system security and their ISO/IEC 27001 certification.

Reporting a security vulnerability#

Based on https://supabase.com/.well-known/security.txt.

At Vikunja, we consider the security of the product and our systems a top priority. But no matter how much effort we put into system security, there can still be vulnerabilities present.

If you discover a vulnerability either in the product itself or Vikunja Cloud, we would like to know about it so we can take steps to address it as quickly as possible. We would like to ask you to help us better protect our clients and our systems.

Out of scope vulnerabilities:#

Please do the following:#

What we promise:#

PGP-Key#

PGP-Key: 2DD15B4BBC0FFB1AEF056662182B59A2D78D7303

You can download the public key from here or here or here.