Nyaya ships no server and stores no user data: the demo runs in the browser and the CLI runs locally. If you find a problem anyway — a credential in the history, a dependency with a known vulnerability, a way to make the retriever fetch something it should not — open a GitHub issue marked security, or, if it should not be public, contact the maintainer through the GitHub profile first. Please give a week before disclosing.
Supported: the latest tagged release (v0.3.0). Dependencies are pinned in requirements.lock.