wikai
Download

Security

In plain English

Found a security issue? Email us — we acknowledge within 72 hours and work to a coordinated disclosure. Security advisories are published on this page.

Reporting a vulnerability

If you’ve found a security issue in Wikai or this website, please email security@wikai.app with the details and, where possible, steps to reproduce.

Please don’t open a public issue for security reports, and please don’t test against other people’s machines or data.

What to expect

  • Acknowledgement within 72 hours.
  • We’ll work with you on a fix and a coordinated disclosure, typically within 90 days.
  • There’s no paid bug-bounty programme yet, but if you’d like credit for a valid report, we’re glad to name you in the release notes.

Scope

The Wikai desktop application and wikai.app. Wikai is local-first — your wikis live on your own disk — so the most sensitive data never reaches our servers in the first place.

Security advisories

Advisories are published here, and summarised in the changelog. If something needs you to act, it will also appear in the app’s update notes.

An advisory says what the problem is, which versions are affected, what we’ve done about it, and what you should do — which is usually: update.

We’d rather tell you about something small than leave you guessing.

Reporting to the authorities

From 11 September 2026, the EU Cyber Resilience Act requires makers of software placed on the EU market to report actively exploited vulnerabilities and severe security incidents to the authorities, and to inform affected users. Wikai is in scope, including versions already released.

If we become aware that a vulnerability in Wikai is being actively exploited, or of a severe incident affecting the app’s security, we will:

  • Within 24 hours — send an early-warning notification to the Centre for Cybersecurity Belgium (CCB), which is Belgium’s national CSIRT, and to ENISA, through the EU’s single reporting platform.
  • Within 72 hours — follow up with what we know and what mitigations exist.
  • Within 14 days of a fix being available — file a final report. For a severe incident, within one month.

And we will tell you, here, as soon as we can do so without making the problem worse for people who haven’t updated yet.

Reporting to a regulator is not a substitute for telling you. The advisory on this page is the part that matters to you, and it is the part we care about getting right.

Last updated 2026-07-20.