Security

Report issues privately and safely.

A precise, limited report helps fix a vulnerability without further exposing people, data, or systems.

Last updated:

Private reporting channel

Send the smallest useful initial report to security@loqy.work.

The authoritative private reporting route is published in security.txt.

  • the exact loqy version, source revision, affected URL, and macOS version where relevant;
  • minimal reproduction steps, prerequisites, expected behavior, and observed behavior;
  • your impact assessment and whether the issue is reliably reproducible, without accessing anyone else’s data;
  • a manually reviewed, content-free loqy diagnostic export when needed.

Keep secrets and personal content out

Do not send passwords, provider keys, tokens, cookies, authorization headers, raw Keychain or crash-report exports, private documents, full workspaces, databases, or unrelated personal data. Remove entire sensitive lines or files rather than relying on cosmetic redaction.

Before sending any attachment, remove secrets and personal data, and keep only what a maintainer needs to reproduce the problem.

Good-faith research boundary

Responsible research is welcome only within the following boundary. This policy is not permission to break the law, access third-party data, or test systems you do not own or control.

  • test only your own account, device, data, and authorized loqy surfaces;
  • do not use denial of service, spam, social engineering, physical attacks, destructive payloads, persistence, or data exfiltration;
  • stop after proving the minimum issue and do not retain, alter, copy, or disclose data you encounter unintentionally;
  • stop immediately and report privately if personal data, credentials, another person’s content, or broader access becomes visible.

Triage and coordinated disclosure

Reports are prioritized by credible impact and assessed against the exact affected version for reachability, impact, exploitability, and existing controls. If a report falls outside security, loqy redirects it to the appropriate route when possible. loqy keeps the reporter informed when practicable.

Share a suspected vulnerability privately first and allow reasonable time to assess a fix or mitigation. loqy coordinates disclosure case by case, balancing remediation, affected people, and the public interest.

Security and personal-data incidents

Credible incidents are contained, documented, and assessed. Personal-data breaches are handled under the GDPR risk thresholds, including CNIL notification where required and communication to affected people where a high risk is likely.

For a privacy-rights request without a security vulnerability, contact privacy@loqy.work.

Crashes, recovery, and data loss

A crash, failed update, or suspected data loss should start with product support unless it also indicates unauthorized access, unsafe deletion, credential exposure, or another security boundary failure. Preserve the current state and contact support@loqy.work.