Please do not disclose suspected security vulnerabilities in public Discussions, repository content, or social channels.
Use GitHub private vulnerability reporting for issues involving the Termark desktop or mobile applications, update and distribution channels, authentication, local data protection, credential handling, sync, SSH/SFTP behavior, or official web services.
Include only the information needed to reproduce and assess the issue:
- affected Termark platform and version;
- expected and observed behavior;
- minimal reproduction steps;
- security impact and prerequisites;
- relevant logs with credentials, hostnames, addresses, tokens, and personal data removed.
Do not upload private keys, passwords, API tokens, production server details, customer data, or other secrets.
We will review valid reports and communicate through the private advisory. Response and remediation timing depends on severity, reproducibility, and release constraints.
Supported release status is maintained in the desktop changelog and mobile changelog. Reports about third-party services, unsupported versions, social engineering, or vulnerabilities that require already-compromised devices may be outside scope, but can still be submitted privately when uncertain.