Home

Security policy

Security

OpenReader is a small open-source project. If you find a vulnerability in the app, website, shared reader package, or local TTS backend, please report it privately before posting publicly.

Report privately

Please do not open a public GitHub issue for suspected vulnerabilities. Email the security inbox first.

What helps

A short description, steps to reproduce, affected version, platform, and logs are enough to start.

Disclosure

We try to acknowledge reports within 72 hours and coordinate fixes before public disclosure.

For details, see the repository security policy.

SECURITY.md