| Version | Supported |
|---|---|
| 0.6.x | ✅ |
| < 0.6 | ❌ |
We take security issues seriously. If you discover a security vulnerability, please report it responsibly.
Please DO NOT file a public GitHub issue for security vulnerabilities.
Instead, please report them via one of the following:
- Email: security@alloomi.ai
- GitHub Private Vulnerability Reporting (available on the Security tab of this repository)
When reporting, please include:
- A clear description of the vulnerability
- Steps to reproduce the issue
- Potential impact of the vulnerability
- Any suggested mitigations (if known)
- We will acknowledge receipt of your report within 48 hours
- We will provide an estimated timeline for a fix within 7 days
- We will keep you updated on our progress
- Once the vulnerability is fixed, we will credit you in the release notes (unless you prefer to remain anonymous)
Security issues in the following areas are in scope:
- Authentication and authorization mechanisms
- Data encryption and storage security
- API endpoints and integrations
- Local data storage and IndexedDB/SQLite security
- Desktop application security (Tauri/Rust backend)
- Third-party dependency vulnerabilities
- Social engineering attacks
- Physical security
- Denial of service attacks against public infrastructure
- Issues related to user's own server/infrastructure configuration
Security updates will be released as patch versions (e.g., 0.6.1) and announced via:
- GitHub Security Advisories
- Release notes on GitHub Releases
- Discord announcements
When using OpenLoomi:
- Keep your installation updated to the latest version
- Review connector permissions before granting access
- Use strong authentication for integrated services (Gmail, Slack, etc.)
- Store your API keys securely and never share them