Skip to content

Security: rachts/DocEasy

Security

SECURITY.md

Security Policy

DocEasy is engineered from first principles around data minimization, client-side isolation, and verifiable zero telemetry. We take security and privacy reports very seriously.

Supported Versions

Version Supported
1.0.x
< 1.0

Reporting a Vulnerability

If you discover a potential security vulnerability, security flaw, or data privacy violation in DocEasy, please report it privately.

DO NOT create a public GitHub issue.

Reporting Contact

Please email the maintainers directly at: [email protected]

Please include in your report:

  1. Type of issue (e.g. unexpected network transmission, client-side memory leak, RLS bypass, CSP flaw).
  2. Step-by-step instructions to reproduce the issue.
  3. Proof-of-concept payload or network capture, if available.
  4. The impact of the vulnerability.

Response Timeline

  • Initial Response: Within 48 hours of receipt.
  • Triage & Status Update: Within 5 business days.
  • Resolution & Release: We will coordinate a patched release and acknowledge your responsible disclosure.

There aren't any published security advisories