Security policy
Security
OpenReader is a small open-source project. If you find a vulnerability in the app, website, shared reader package, or local TTS backend, please report it privately before posting publicly.
Report privately
Please do not open a public GitHub issue for suspected vulnerabilities. Email the security inbox first.
What helps
A short description, steps to reproduce, affected version, platform, and logs are enough to start.
Disclosure
We try to acknowledge reports within 72 hours and coordinate fixes before public disclosure.
For details, see the repository security policy.
SECURITY.md