At Bored Polymath Studios, the security and privacy of our users are foundational. Because AdCleanse operates as an offline-first privacy console interacting with user credentials and local encrypted storage, we take reports of security flaws seriously.
Only the latest active release on the main branch receives active security updates and vulnerability patches.
| Version | Supported |
|---|---|
| 0.1.x | ✅ |
| < 0.1.0 | ❌ |
We strongly encourage responsible, coordinated vulnerability disclosure.
Please submit security vulnerabilities privately using GitHub's Private Vulnerability Reporting feature:
- Direct Link: Open Private Advisory
This allows us to review, collaborate on a patch, and coordinate a secure fix before public disclosure.
If you cannot use GitHub's advisory system, you may contact the maintainers directly:
- Email: boredpolymath@proton.me
- Subject:
[SECURITY] AdCleanse Vulnerability Report
To help us triage and resolve your report quickly, please include:
- Description: Clear summary of the vulnerability and its potential impact.
- Steps to Reproduce: Detailed reproduction steps, sample payload, or minimal proof of concept (PoC).
- Environment: Target operating system (macOS / Windows / Linux), Tauri version, and build architecture.
- Proposed Fix: Any suggested mitigations or patches (optional).
- Initial Acknowledgment: Within 48 hours of receipt.
- Assessment & Triage: Within 5 business days.
- Remediation & Release: Coordinated fix deployed via a signed release tag and release advisory.