Boldcall

Company

Security

Secret picks are the whole game. If someone could peek, Boldcall wouldn't work. Here's how we stop that, what else we protect, and what's still on our list.

Last updated

Who we're up against

The people most likely to peek aren't hackers. They're your group chat, and at least one of them is good with computers. So we plan for a friend with a hacked phone, some network tools and a free afternoon. They might try reading the app's traffic, changing the app, hitting our server directly or messing with their phone's clock. Picks have to stay secret through all of it, so none of the secret-keeping can happen on the phone.

Secrets stay on our server

Our server never sends you a pick you're not supposed to see. It's not hidden or blurred. It's just not sent. One piece of code sits between the database and every response, and only passes along what you're allowed to see. Before reveal day, that's the call, its date, how many people picked, and your own pick.

Behind that, the database itself refuses to hand anything over unless you're in the group, and no app can read the picks table directly. Reveal day, results and points all run on our server's clock, so a call can't be revealed early or scored twice.

Being straight with you

We don't read group chats, and our support tools don't show picks early. But picks do live in our database, and an engineer with access could technically look. That's true for any app like this. We'd rather say it than pretend we use encryption we don't.

Your account

  • Sign in with Apple, Google or a phone code. No passwords to leak. Codes expire fast and there's a limit on how many you can request.
  • Your sign-in is saved in your phone's secure storage and can be shut off remotely.
  • Everything is encrypted, on the way and while stored, with daily backups.
  • Very few people have access to our live systems. They need two-step sign-in, and every look is logged.
  • Crash reports strip out names, phone numbers, posts and picks before they leave the app.
  • We don't hold payment info, contacts or birthdays. Can't leak what we don't have.

Still on our list

  • No outside security test yet. We'll get one before launch and post about it here.
  • No SOC 2, ISO 27001 or other certifications.
  • No paid bug bounty.
  • No end-to-end encryption. Our server keeps picks secret, which is what lets results work and groups keep their history.

Found a security bug?

Email security@boldcallapp.com with what you found, how to reproduce it, and how you'd like to be credited. We'll reply within 3 business days, have a plan within 10 business days, and let you know when it's fixed. Our security.txt lives at /.well-known/security.txt.

We won't come after you if you're acting in good faith. That means you only use accounts and groups that are yours, don't touch other people's data, don't slow Boldcall down for anyone, don't try to trick our team or partners, and give us a fair chance to fix it before you go public. If you want, we'll thank you by name here.