Skip to content

Security: Lord-shaban/Nota

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

If you find a security vulnerability, please contact us privately at security@notaapp.dev
Do not disclose it publicly until we release a fix.

Supported Versions

Version Supported
main
dev
old branches

Security Practices

  • Firebase Firestore rules restrict unauthorized access.
  • API keys are never committed to the repo.
  • All communications with Gemini API use HTTPS.
  • Sensitive user data is anonymized before AI processing.

Response Process

  1. Confirm receipt within 48h.
  2. Investigate and reproduce issue.
  3. Apply fix and release update.
  4. Credit reporter if applicable.

There aren't any published security advisories