Locuset handles private local memory, so security reports are treated as confidential by default.
Until the first stable release, only the latest commit on main is supported.
Release notes will identify supported stable branches once they exist.
Please do not open a public issue for a suspected vulnerability or include real personal data, credentials, database files, screenshots, or capture output in a report.
Use GitHub's private vulnerability-reporting form for this repository. If that form is unavailable, open a minimal issue asking the maintainers to enable a private reporting channel; do not include exploit details in that issue.
Include:
- the affected commit or version;
- the smallest synthetic reproduction;
- the security boundary that failed;
- expected and observed behavior;
- whether captured content, credentials, or connector permissions were exposed.
We will acknowledge a complete report within seven days. A fix, disclosure timeline, and credit are coordinated with the reporter. Never test against another person's device or data.
The current boundaries and residual risks are documented in
docs/project/security-audit.md, docs/reference/storage-encryption.md,
docs/project/native-capture-security-review.md, and
docs/project/clean-room/threat-model.md. A local build is not equivalent to a
Developer ID signed and notarized public release.