Please report security issues privately through GitHub Security Advisories. Private vulnerability reporting is enabled, so a report reaches the maintainers without ever being public.
Please do not open a public issue, post on social media, or send email for security findings.
- An acknowledgement and an initial severity assessment.
- A fix or a mitigation plan, with a shared view of timing before anything is disclosed.
- Credit in the advisory if you want it, and none if you prefer to stay anonymous.
Reports are read by the maintainers directly. There is no guaranteed response time and no bug bounty.
Security research against the hosted service is welcome and is not a violation of the Terms of Use. While testing, please:
- do not access data of tenants you do not own,
- do not degrade the service for others,
- do not run automated scanners against production.
The hosted service always runs the current main. For the on-device agent, only the
latest release receives fixes.
The Security FAQ and Data Flows pages describe the security model, data handling, and isolation in detail.