Please report security vulnerabilities privately via GitHub Security Advisories rather than opening a public issue.
You should receive a response within a few days. Please include steps to reproduce and the affected version/platform.
- Viscriptix never stores API keys — they are read only from environment
variables (
OPENAI_API_KEY,GOOGLE_API_KEY). A report showing a key being written to disk or logs would be a serious bug. - The app has no telemetry, accounts, or update phone-home; media is sent only to the AI provider the user selects.
Only the latest release receives security fixes.