Thank you for helping keep Reckonry secure.
Reckonry is designed to process financial and accounting data. Because of this, security and responsible disclosure are extremely important.
| Version | Supported |
|---|---|
| Latest stable | ✅ |
| Previous stable | ✅ |
| Older versions | ❌ |
Please do not report security vulnerabilities through public GitHub Issues.
Instead:
- Open a private GitHub Security Advisory if available.
- If private reporting is not available yet, contact the maintainers using the project's security contact once published.
Please include as much information as possible:
- Reckonry version
- Operating System
- .NET version
- Steps to reproduce
- Expected behavior
- Actual behavior
- Screenshots (if applicable)
- Logs (after removing sensitive information)
Never include:
- Exchange API keys
- Wallet private keys
- Seed phrases
- Personal financial information
- Tax reports
- Exchange exports
- Personally identifiable information (PII)
If possible, reproduce the issue using anonymized or synthetic data.
Reckonry follows several core security principles:
- Privacy by default
- No hidden network communication
- No telemetry without explicit consent
- Immutable audit trail
- Full source traceability
- No invented financial data
- Secure handling of sensitive files
- Reproducible calculations
Security reports may include issues related to:
- Data integrity
- Financial calculations
- Ledger corruption
- Import validation
- Report generation
- Sensitive data exposure
- Dependency vulnerabilities
- Supply-chain attacks
- PDF generation
- Plugin isolation
- Cryptographic verification
- Hash generation
The following are generally considered out of scope:
- Documentation typos
- Feature requests
- UI improvements
- Unsupported operating systems
- Issues caused by modified third-party software
When a valid security issue is reported:
- We will acknowledge the report.
- We will investigate the issue.
- A fix will be prepared.
- A new release will be published.
- The reporter will be credited unless anonymity is requested.
Please allow reasonable time for a fix before publicly disclosing vulnerabilities.
Responsible disclosure helps protect all Reckonry users.
Security is not only about preventing attacks.
For Reckonry, security also means:
- Every financial value must remain explainable.
- Every generated report must remain reproducible.
- Every imported transaction must remain traceable.
- Users must always remain in control of their data.
Thank you for helping make Reckonry a trustworthy open-source platform.