Skip to content

Security: Lithographic/viscriptix-app

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

Please report security vulnerabilities privately via GitHub Security Advisories rather than opening a public issue.

You should receive a response within a few days. Please include steps to reproduce and the affected version/platform.

Scope notes

  • Viscriptix never stores API keys — they are read only from environment variables (OPENAI_API_KEY, GOOGLE_API_KEY). A report showing a key being written to disk or logs would be a serious bug.
  • The app has no telemetry, accounts, or update phone-home; media is sent only to the AI provider the user selects.

Supported Versions

Only the latest release receives security fixes.

There aren't any published security advisories