Information Security Policy
Last updated 10 August 2026.
Principles
- ReFineID is open source. The implementations can be read and audited at github.com/ReFineID.
- The applications are sandboxed, keep the smallest network surface the signature formats require, and never write PINs, card access numbers or card data to logs or diagnostics. Production builds write no diagnostics at all. The debug traces exist only in development builds, and releases are verified against their binaries.
- Security-relevant dependencies are minimal and pinned. Releases are built from tagged, reviewed source.
Reporting a vulnerability
Report vulnerabilities however suits you. A public issue on GitHub is welcome, and so is private email to petri.koistinen@refineid.fi. You will receive an acknowledgement within a month.
Scope and support
The policy covers the ReFineID applications and the services at refineid.fi. The latest released versions are supported. Machine-readable contact details are published at /.well-known/security.txt.