Report vulnerabilities privately to security@silentsilo.com, or with Report a vulnerability under this repository's Security tab. Please do not open a public issue for anything that could be a vulnerability.
The same address covers silentsilo/core and silentsilo/desktop. Report to whichever repository you found it in; it reaches the same person either way.
This is a one-person project, so reports are read by one person: the aim is an acknowledgement within 72 hours. Please include steps to reproduce, the device and OS version, and the commit or release you tested against.
This repository is the mobile applications: the key held in the phone's hardware, the biometric prompt, how the app stores its settings, what it leaves on the device while unlocked and after it locks, and the clipboard. The cryptography and the formats are core's, and so is their policy.