Send vulnerability reports to security@locoris.app.
Include
- affected Locoris version and platform;
- affected website, endpoint or synchronization method;
- reproducible steps and expected impact;
- a safe proof of concept where appropriate;
- whether any user data may have been exposed.
Do not include
Do not send private-vault secrets, complete payment credentials or personal data belonging to another user. Avoid destructive testing, persistence and public disclosure before there is a reasonable opportunity to investigate.
Response
Locoris will attempt to acknowledge complete reports, assess severity and coordinate remediation and disclosure. Response timing depends on impact, reproducibility and available resources.