If you discover a security vulnerability in docolin, please email security@docolin.com.
The mailbox is hosted on Proton Mail, so:
- Mail sent from another Proton Mail account is end-to-end encrypted automatically.
- Mail sent from any other provider can be encrypted with PGP (request our public key in your first message), or sent via Proton's password-protected reply once we respond.
Please do not file public issues, discussions, or pull requests for security reports. Coordinated disclosure protects users while we ship a fix.
When you report, please include:
- A description of the issue and its impact
- Steps to reproduce, or a proof of concept
- Affected versions, if known
- Your name or handle for credit (optional)
- We aim to acknowledge new reports within 72 hours.
- We will keep you updated as we triage, fix, and release.
- Once a fix is released, we will publish an advisory and credit you (unless you prefer to stay anonymous).
This policy covers code in this repository and any official docolin-dev services. Third-party dependencies should be reported upstream, but feel free to CC us if a vulnerability has direct impact on docolin.
docolin is pre-alpha. There are no supported releases yet. Security reports against main are still very welcome.