Security

Report issues privately and safely.

Please do not publish a suspected vulnerability before there is a safe path to assess and address it.

What to send first

Send the smallest useful initial report to security@loqy.work.

  • the loqy version and macOS version concerned;
  • minimal reproduction steps, expected behavior, and observed behavior;
  • your assessment of impact, without accessing other people’s data;
  • a loqy diagnostic export generated through the documented no-secret procedure, if available.

Keep secrets and personal content out

Do not send passwords, provider keys, tokens, raw Keychain exports, private documents, full workspaces, or unrelated personal data. Redact paths, names, addresses, and document contents unless a specific item is strictly required and explicitly requested through the private channel.

Current response boundary

loqy is pre-release and does not currently promise a bug bounty, guaranteed response time, or remediation SLA. Reports are acknowledged and prioritized according to credible impact and available maintainer capacity.

GitHub private vulnerability reporting will be offered only after that channel has been verified on the public repository. Until then, email is the authoritative private route.