Skip to content

Security: voidhashcom/voidhash

Security

SECURITY.md

Security Policy

Supported Versions

Voidhash is currently in private alpha and is not yet supported for production use. Security fixes are applied to the latest main branch. Older commits, preview builds, and unpublished alpha artifacts are not supported.

This policy will be updated with a version support table before the first public release.

Reporting a Vulnerability

Please report suspected vulnerabilities privately to security@voidhash.com. Do not open a public issue, discussion, or pull request for a vulnerability.

Include the affected component, reproduction steps, expected impact, and any suggested mitigation. We will acknowledge the report, investigate it, and coordinate remediation and disclosure with the reporter. Please avoid accessing data that is not yours, disrupting services, or exploiting a finding beyond what is necessary to demonstrate it.

The current backend threat model and publication risks are documented in docs/security/backend-threat-model.md.

There aren't any published security advisories