TYPIQ
For Schools For Kids Pricing Blog
EN ES PT DE NL SV IT FR PL EL RO
School login Download
SECURITY

Security Policy v1.0 — March 2026

Last updated: March 29, 2026 Compliant with: EU Cyber Resilience Act (CRA) Regulation 2024/2847, EU Product Liability Directive 2024/2853, Romanian DNSC requirements, ENISA guidelines
This document describes SIBSTIL DOORS SRL's security commitments for the Typiq desktop application, our vulnerability disclosure process, and how we handle security incidents. It applies to all versions of Typiq.

1. Our Security Commitments

SIBSTIL DOORS SRL commits to the following security standards for Typiq:

  • Secure by design: The application uses contextIsolation and sandboxed rendering (Electron security best practices). nodeIntegration is disabled. All IPC communication uses contextBridge.
  • No unnecessary data collection: The application does not collect or transmit personal data during offline use.
  • Local data only: Progress data and settings are stored locally in the user's profile directory.
  • HTTPS only: All network communication from the application and website uses HTTPS with valid certificates.
  • Dependency management: We monitor third-party dependencies (Electron, Node.js packages) for known vulnerabilities using automated tools.
  • Security support period: Minimum 3 years from purchase date for Personal license holders.

2. Supported Versions

VersionStatusSecurity Updates
1.x (current)✅ ActiveYes — full support
Future versionsTo be announcedYes

We strongly recommend always using the latest version of Typiq to benefit from the most recent security patches.

3. Vulnerability Disclosure Policy

We welcome responsible disclosure of security vulnerabilities. If you discover a security issue in Typiq, please follow the process below.

Report a vulnerability: Email support@typiq-app.com with subject line: [SECURITY] Typiq vulnerability report

Please include in your report:

  • Description of the vulnerability
  • Typiq version affected
  • Operating system and version
  • Steps to reproduce
  • Potential impact assessment (if known)
  • Your contact information (for follow-up)

4. Our Response Process

TimelineAction
Within 48 hoursAcknowledge receipt of your report
Within 7 daysInitial assessment and severity classification
Within 30 daysPatch development and testing (critical vulnerabilities prioritized)
Within 45 daysRelease of patched version and public disclosure (coordinated with reporter)

We ask that you:

  • Do not publicly disclose the vulnerability before we have released a patch (coordinated disclosure)
  • Do not exploit the vulnerability beyond what is necessary for proof of concept
  • Do not access or modify user data

We will not pursue legal action against researchers who act in good faith and follow this policy.

5. Security Incident Response (CRA Art. 14)

In accordance with the EU Cyber Resilience Act (Regulation 2024/2847) and applicable Romanian cybersecurity law:

  • Security incidents affecting Typiq will be reported to DNSC (Directoratul Național de Securitate Cibernetică) within 24 hours of discovery.
  • Affected users will be notified within 72 hours of a breach confirmed to affect their data, in accordance with GDPR Art. 33-34.
  • A detailed incident report will be provided within 30 days of the incident.

6. Known Security Considerations

Users should be aware of the following:

  • License file: The license file (license.json) is stored in your user profile directory. Do not manually modify this file. Unauthorized modification may result in license deactivation.
  • macOS Gatekeeper: the app is signed with an Apple Developer ID and notarized by Apple. Gatekeeper opens it without a first-launch warning.
  • Windows SmartScreen: The installer is digitally signed by SIBSTIL DOORS SRL (Microsoft Trusted Signing). If SmartScreen still shows a reputation notice for a new release, confirm the publisher reads SIBSTIL DOORS SRL, then click "More info" → "Run anyway."
  • Internet connection: The application requires internet access only for license activation. Normal use is fully offline.

7. Third-Party Dependencies

Typiq uses the following major open-source components. We monitor these for security advisories:

ComponentPurposeSecurity Monitoring
Electron v33Desktop application frameworkGitHub Security Advisories
Node.js v22RuntimeNode.js Security Releases
node-machine-idHardware fingerprintnpm audit

8. Contact

Security reports: support@typiq-app.com
Subject line: [SECURITY] Typiq vulnerability report
SIBSTIL DOORS SRL, Sibiu, România

9. Updates to This Policy

This policy will be reviewed and updated at least annually, or following any significant security incident. The current version is always available at typiq-app.com/security.

TYPIQ

Typiq is a professional desktop application for learning and mastering touch typing. Available for Windows, macOS, and Linux.

Product
  • Home
  • Buy License
  • Install Guide
Solutions
  • For Schools
  • For Kids
Legal
  • Privacy
  • Terms
  • Refund
  • Security
  • Legal Notice
  • Cookies
© 2026 Typiq. All rights reserved.