Nome
Menu

SECURITY

Security and reporting

Security is not a slogan. It comes from knowing where you download from, how to verify, and what to do when something looks wrong.

  • Signature verification
  • Official source
  • Careful reporting
Security centerN

INSTALLATION CHECK

Package details detected

Compare every item with the details published on the official site.

Official sourcenome.im
Current version6.5.6 (358)
SHA-256fcd2522a…ca7d363
Signing statusNon-production!
View full verification

Install only files whose origin you can confirm

Safety check

Trust only what you can verify

Public download and reporting flows should be verifiable and trackable.

This is not a public support ticket page.

Download and safety facts

Release baseline

https://github.com/cxhihilwb123-hash/nome/tree/d23d3f02fc3a99887ffe14919421231d74ab28d0

Current version

v6.5.6 (358) · ARM64 · Official web release

Install source

Only obtain the APK from the official download page

Signing

Non-production signing

Until a dedicated security contact channel is published, do not expose vulnerability details on public pages.

Confirm the download origin

Use only the HTTPS download link provided by the current official Nome site. Public downloads do not require an invite and must not redirect to an R2 management address.

Verify SHA-256

Use `shasum -a 256 filename` on macOS/Linux or `Get-FileHash filename -Algorithm SHA256` in Windows PowerShell. It must exactly match the full digest on the download page.

Understand the current signing state

The APK is a non-production-signed debug web build, not a Google Play build. Android's unknown-source warning is an expected risk disclosure and should not be bypassed or hidden.

Back up before installing or migrating

A later production-signed build may not replace the current development package. Before deletion, migration, or package change, use the in-app backup and migration functions and verify the backup.

Security reporting

Nome's dedicated security contact channel is awaiting external configuration. Until a verified channel is published here, do not send vulnerability details, tokens, invites, backups, or private data through public issues, application-purpose text, or ordinary email.

Nome release baseline

d23d3f02fc3a99887ffe14919421231d74ab28d0

The fixed baseline link is used for review and comparison.