Skip to content

Security: solun-pm/solun

Security

SECURITY.md

Security Policy

Introduction

Solun is a service that provides you the ability to share files, text, and emails with end-to-end encryption, giving you peace of mind concerning your privacy. This project has been long in the making, with the primary goal of creating a service that does not rely on external services such as Whatsapp, Telegram, Signal, etc.

Our Commitment

We prioritize the security of our users' data and privacy. We take all reported vulnerabilities seriously and will review each of them thoroughly. While we currently do not offer a bounty program, we will recognize your effort by crediting your GitHub account in the acknowledgments section of our application's documentation.

Reporting a Vulnerability

If you come across a potential security issue within our system, we urge you to disclose it responsibly. Please follow these steps:

  1. Write an email detailing the potential security issue. Include as much information as possible to help our security team understand and reproduce the issue. This could include things like reproduction steps, the impact of the issue, and any potential fixes you can think of.
  2. Send this email to [email protected]. Please do not disclose the potential issue publicly.
  3. Await our response. We strive to respond to all vulnerability reports within a reasonable timeframe, but we ask for your patience as we work to verify the issue and potentially implement a fix.

Policy on Public Disclosure

In the interest of the safety of our users, we ask that you do not disclose any information about potential security issues publicly until we've had a chance to investigate and respond. We appreciate your understanding and cooperation in this matter.

Acknowledgments

We value the effort of security researchers and community members who take time to identify and responsibly report potential security vulnerabilities. As a token of our appreciation, we will acknowledge their contribution by crediting their GitHub account in the acknowledgments section of our application's documentation.

Please note that this security policy is subject to change, and we encourage you to review it regularly to stay informed about our practices and expectations.

There aren’t any published security advisories