Security
GOTNULL PTY. LTD. takes the security of SocialMesh and our users seriously. This page describes our approach and how to report an issue.
Reporting a vulnerability
If you believe you have found a security vulnerability in SocialMesh or in this website, please email hello@gotnull.com with “Security report” in the subject line. Please give us a reasonable opportunity to investigate and address the issue before any public disclosure.
A machine-readable contact is also published at /.well-known/security.txt.
Our approach
- We aim to follow platform security guidance for iOS and Android and to ship updates through the official App Store and Google Play channels.
- SocialMesh communicates with Meshtastic devices over Bluetooth. Meshtastic supports encrypted channels at the protocol level; channel keys are managed by the user and their devices.
- Data handling, including any optional connected features, is described in our Privacy Policy.
What we do not claim
We do not make absolute security guarantees. No software is “unhackable” or fully secure in every circumstance. Local mesh radio is best-effort and is not a substitute for licensed emergency communications.
How your data is handled
SocialMesh connects to Meshtastic radios over Bluetooth. Mesh messages are carried by the Meshtastic network and are kept only on your device, not on our servers. Message content, node information, and connection data are processed on your device and are not transmitted to us. Optional account and social features store data on Google Firebase, and optional analytics and crash reporting are turned off by default. Because mesh transmissions are relayed by other devices in a decentralised network, a message cannot be recalled once it has been sent over radio.