| Version | Supported |
|---|---|
| 1.0.x | ✅ |
MrNothing Shield is a security tool, and we take its security seriously.
- Do NOT open a public issue for security vulnerabilities
- Email security disclosures to:
security@voltex.network - Include detailed reproduction steps and impact assessment
- Allow 90 days for remediation before public disclosure
- We will acknowledge receipt within 48 hours
- Vulnerabilities in the Shield framework itself
- Bypass techniques that allow malware to evade detection
- False negatives (undetected spyware)
- Privacy issues in data handling
- Spyware development assistance (we build defenses, not weapons)
- Vulnerabilities in third-party dependencies (report to upstream)
- General security questions (use Discussions instead)
All audit reports include SHA-256 evidence hashes and are cryptographically signed to prevent tampering.
- All scans run locally on the device
- No telemetry or data collection
- No network connections except for IOC database updates (optional)
- Audit reports are stored with restrictive permissions
- ADB connections require explicit authorization
- Root-required modules are opt-in
- Reports exclude sensitive data (passwords, tokens)
- Automatic cleanup of temporary forensic files
We participate in the VOID//Bounty program. Security researchers who report valid vulnerabilities may be eligible for rewards.