We actively provide security updates and patches for the following versions:
| Version | Supported |
|---|---|
| 1.x.x | β |
| < 1.0.0 | β |
We take the security of Vitralis and user workshop data seriously. If you discover a security vulnerability, please report it responsibly:
- Do not create a public GitHub issue.
- Use GitHub's private vulnerability reporting feature on the repository:
- Navigate to Security β Advisories β Report a vulnerability.
- Or email us at
security@vitralis.app.
- Provide a detailed description of the vulnerability, reproduction steps, and potential impact.
- Initial Acknowledgement: Within 48 hours.
- Vulnerability Assessment & Triage: Within 5 business days.
- Fix & Public Advisory: Released as a patch version via automated release pipeline.
- Zero-Cloud Storage: Vitralis operates 100% locally in the user's browser using
localStorage. No formulas, recipes, or client quotes are transmitted to external servers. - Content Security: All inputs are sanitized, and PDF quotation exports are rendered directly in the DOM using print stylesheets.