Desktop AI Companion does not yet have a public release. Security reports are still welcome for the current repository and for private or CI builds identified by an exact 40-character Git commit.
Use GitHub's private vulnerability-reporting form when it is available:
https://github.com/bigfnj/desktop-ai-companion/security/advisories/new
If that private form is unavailable, open a minimal public issue asking the maintainer to establish a private contact channel. Do not include exploit details, API keys, screenshots, OCR text, conversation history, settings files, personal data, or other secrets in a public issue.
Include the affected commit or published version, artifact type, Windows version, reproduction conditions, impact, and the least-sensitive proof needed to confirm the problem. Do not test against systems, accounts, endpoints, or data you do not own or have explicit permission to use.
There is no guaranteed response time or security service-level agreement. General troubleshooting belongs in SUPPORT.md; privacy behavior is documented in PRIVACY.md.