Security policy
Please report vulnerabilities privately first. Public advisories should follow after a fix or mitigation is available.
Security priorities
Supply-chain integrity, endpoint hardening, privacy defaults, crypto-agility and clear incident response.
Threat model summary
- Remote compromise of user applications and browsers.
- Supply-chain tampering with releases or configuration.
- Harvest-now-decrypt-later risks for sensitive traffic.
- Local device theft or accidental data exposure.
Verification checklist
- Verify checksums.
- Verify signatures when published.
- Confirm release tag and build log.
- Review SBOM and known-issues page.