Send vulnerability reports to security@locoris.app.

Include

  • affected Locoris version and platform;
  • affected website, endpoint or synchronization method;
  • reproducible steps and expected impact;
  • a safe proof of concept where appropriate;
  • whether any user data may have been exposed.

Do not include

Do not send private-vault secrets, complete payment credentials or personal data belonging to another user. Avoid destructive testing, persistence and public disclosure before there is a reasonable opportunity to investigate.

Response

Locoris will attempt to acknowledge complete reports, assess severity and coordinate remediation and disclosure. Response timing depends on impact, reproducibility and available resources.