Sillage stores private records, attachments, login sessions, and encrypted AI API keys. Do not disclose vulnerabilities, real data, secrets, or sensitive logs in public issues.
Report vulnerabilities privately through GitHub Private Vulnerability Reporting. Include the affected version or commit, impact, prerequisites, minimal reproduction steps using synthetic data, and any known mitigations.
Security fixes target the latest release and main; older versions are not guaranteed separate maintenance. See the canonical Sillage security policy for supported versions, response expectations, and deployment responsibilities.