▸ Security
Systems Operational

Security at Muzzish

How we protect your data across every platform

Last updated: July 2026

01Our Commitment to Security

At Muzzish, we believe that security is a fundamental right, not an afterthought. Our cross-platform ecosystem—spanning browser extensions, Android, iOS, and the web—is designed from the ground up to protect your data. We employ a defense-in-depth strategy, integrating security into every phase of our development lifecycle to ensure that your information remains confidential, integral, and available only to you.

02Infrastructure & Data Protection

We utilize industry-standard cryptographic protocols to secure your data across our entire infrastructure:

  • Encryption at Rest: All user data is encrypted at rest using AES-256 encryption, ensuring that even in the event of a physical breach, your data remains secure.
  • Encryption in Transit: All communications between our client applications and servers are secured using TLS 1.3, protecting data against interception and tampering.
  • Secure Sync Protocol: Our proprietary sync engine utilizes secure session management and token-based authentication to seamlessly and securely synchronize data across your devices.

03Application Security

Our engineering team follows rigorous secure development practices to mitigate vulnerabilities before they reach production:

  • Code Reviews & Scanning: Every commit undergoes peer review and automated dependency scanning to detect known vulnerabilities.
  • Minimal Permissions: Our browser extensions (for Chrome, Edge, and Firefox) and mobile apps request only the absolute minimum permissions required to function.
  • Regular Audits: We conduct periodic internal security audits and threat modeling exercises to evaluate our architecture against emerging threats.

04Responsible Disclosure Program

We recognize that no system is immune to vulnerabilities. We actively encourage and welcome security researchers, developers, and users to report potential security issues to us. We are committed to working closely with the security community to verify and resolve vulnerabilities in a timely and responsible manner.

05How to Report a Vulnerability

Security Report Card

If you believe you have found a security vulnerability, please send an email directly to our security team.

Please include the following information in your report:

  • A detailed description of the vulnerability
  • Clear, step-by-step instructions to reproduce the issue
  • Your assessment of the potential impact
  • Your contact information

Note: PGP key for encrypted communication is coming soon.

06Disclosure Guidelines

In Scope

Our vulnerability disclosure program covers all official Muzzish properties, including:

  • Muzzish Web Application and APIs
  • Muzzish Browser Extensions (Chrome Web Store, Microsoft Edge Add-ons, Firefox Add-ons)
  • Muzzish Mobile Apps (Google Play Store, Apple App Store)

Out of Scope

  • Social engineering (e.g., phishing) against Muzzish employees or users
  • Denial of Service (DoS/DDoS) attacks
  • Vulnerabilities in third-party services or infrastructure providers
  • Spam or UI/UX bugs lacking a measurable security impact

Rules of Engagement

When conducting security research, please adhere to the following rules:

  • Do not access, modify, or delete data belonging to other users.
  • Do not perform actions that degrade or disrupt our services.
  • Do not exploit a vulnerability beyond what is necessary to demonstrate it.
  • Keep information about any vulnerabilities confidential until we have resolved them.

07Response Timeline

We value your effort and commit to providing timely updates on your report. Our target timelines are as follows:

AcknowledgmentWithin 48 hours
Initial AssessmentWithin 5 business days

Resolution Targets by Severity

Critical7 days
High14 days
Medium30 days
Low90 days

08Contact

Depending on your needs, please direct your inquiries to the appropriate channel:

Security Issuessecurity@muzzish.com
Privacy Concernsprivacy@muzzish.com
General Inquiriessupport@muzzish.com