Do not open a public issue for a security problem. Use GitHub's private
vulnerability reporting,
or email support@vortilis.com with security in the subject.
Include what you did, what happened, your VorPilot version (Settings → About) and your operating system. A proof of concept helps.
We will confirm we received your report and tell you what we decide to do about it. We do not promise a response time — better to say so than to publish a number we cannot keep. There is no bug bounty.
Fixes ship in the current release of your channel and are not backported. The application updates itself.
In scope: the Desktop application, Server and its Helm chart, vortilis.com and
its subdomains, and the release artefacts we publish.
Out of scope: denial of service, load testing, scanner output with no demonstrated impact, missing headers with nothing behind them, and anything needing a machine or cluster you do not control.
Every release ships a signed checksums.txt, and the
Download page publishes the public key and the
commands to check a file against it. A download that does not verify is itself
worth reporting.