Please do not disclose security issues in public GitHub Issues.
Send reports to:
support@nokuo.xyz
Include:
- Affected version
- Operating system
- Clear reproduction steps
- Impact description
- Any logs or screenshots with secrets fully redacted
Do not include real secrets, recovery keys, master passwords, private keys, or private Vault content.
In scope:
- Local Vault encryption and unlock flow
- Recovery-key flow
- Sync and restore handling of encrypted Vault files
- Installer integrity issues
- Bugs that can expose plaintext secrets
Out of scope:
- Social engineering
- Physical access to an unlocked device
- Issues requiring malware already running as the user
- Reports without enough detail to reproduce or evaluate