Skip to content

Security: atomicdjt/weavestudio

Security

SECURITY.md

Security Policy

Supported version

Security reports apply to the current default branch and the current public demo.

Reporting a vulnerability

Please do not open a public issue for a suspected vulnerability. Send a concise report to davidelsey9513@gmail.com with reproduction steps, affected route or component, impact, and any proposed mitigation.

Do not include API keys, private workflow content, or personal data in a report. Reports are reviewed on a best-effort basis; no formal response-time or bug-bounty commitment is made.

Product boundary

WeaveStudio is a local-first browser application. Optional direct OpenAI and Gemini requests require a user-entered key and explicit per-request consent. API keys are intended to remain volatile and are not included in exports.

There aren't any published security advisories