Skip to content

Security: pxinnovative/px-tunnel

Security

SECURITY.md

Security Policy

Supported Versions

Version Supported
Latest Yes

Reporting a Vulnerability

If you discover a security vulnerability in PX Tunnel, please do not open a public issue.

Instead, report it responsibly:

  1. Email: github@pxinnovative.com
  2. Subject: [SECURITY] PX Tunnel — <brief description>
  3. Include:
    • Description of the vulnerability
    • Steps to reproduce
    • Potential impact
    • Suggested fix (if you have one)

What to Expect

  • Acknowledgment within 48 hours
  • Assessment within 7 days
  • Fix or mitigation as soon as possible, depending on severity
  • Credit in the release notes (unless you prefer to remain anonymous)

Scope

This policy covers the PX Tunnel application and its dependencies as distributed in this repository. It does not cover third-party tools (Headscale, WireGuard, the Tailscale client) — report those to their respective maintainers.

Privacy Note

PX Tunnel is self-hosted: it runs entirely on your own infrastructure, makes no outbound calls, and includes no telemetry or analytics. Your mesh data never leaves your host. If you believe this guarantee has been compromised, please report it immediately.

Thank You

We take security seriously and appreciate the community's help in keeping PX Tunnel safe for everyone.

There aren't any published security advisories