Security
Munadi device, Munadi Connect app, and munadi.tech services · Last updated 29 August 2026
Reporting a vulnerability
If you believe you have found a security issue in the Munadi M01 device, the Munadi Connect apps, the api.munadi.tech service, or this website, please email security@munadi.tech. Include what you found, the component and version, and steps to reproduce it.
You will receive an acknowledgement within 3 business days and an assessment within 14 days. We follow coordinated disclosure with a 90 day window from your report, extendable by agreement, and shortened if the issue is being exploited in the wild. When a fix ships we publish an advisory on this page and credit you, unless you prefer otherwise.
Safe harbour
Good-faith research within this policy will not be met with legal action. Stay within it: no access to data that is not yours beyond a minimal proof of concept, no service disruption, and no social engineering of individuals.
Out of scope
- The published app-review account (
demo@munadi.tech): it is a deliberately public credential for app-store review, not a finding. - Volumetric denial of service.
- Reports about third-party services we do not operate.
Security updates and support period
Security fixes target the latest released firmware and app versions, provided free of charge. The Munadi M01 carries a security support commitment of five years from the date it is first placed on the market; the concrete end-of-support month and year will be published here at launch and stated at the point of sale.
At end of support the device degrades rather than dies: it keeps computing prayer times and calling the adhan entirely offline. What stops are security updates, app-driven features, mosque timetables, and pairing to new accounts.
Advisories
Published security advisories for fixed vulnerabilities will appear here, each carrying the affected versions, the fixed version, severity, and remediation steps. None have been published to date; when one is, it appears at munadi.tech/security/advisories.
Machine-readable pointer
This policy is referenced from /.well-known/security.txt on munadi.tech and api.munadi.tech, per RFC 9116.