Email security@armoryworks.com with the subject [Armory Works Security].
Please don't open a public issue for a vulnerability.
We acknowledge within two business days and aim to ship a fix or a disclosure plan within ten. Tell us what you found, how to reproduce it, and what you think the impact is; if you'd like credit in the release note, say so and how you want to be named.
We won't pursue anyone who reports in good faith, stays within their own data or a test install, and gives us a reasonable window before going public.
These projects are pre-1.0 and ship from main. Fixes land on main and in
the next tagged release; there are no maintained back-branches yet.
Most of what we publish is self-hosted, so the operator owns the deployment's security posture — TLS termination, database credentials, network exposure, backups, and OS patching. A vulnerability in our code is ours; a misconfigured install is something we'll happily help with, but it isn't a security advisory.
If you run one of these and a report affects your data specifically, contact us at the address above rather than filing publicly.