Security

Responsible disclosure for Synapse Tools products.

If you find a security-sensitive issue, report it privately with clear reproduction steps and impact. Public claims should stay aligned with shipped behavior.

Contact[email protected]
SubjectSecurity Report
IncludeProduct, impact, reproduction steps

What to send.

  • Email [email protected] with subject line Security Report.
  • Tell us which product is affected and why the issue is security-sensitive.
  • Include steps to reproduce, impact, screenshots, logs, or proof material when useful.

How to share sensitive details.

  • Avoid public disclosure until the report is acknowledged and reviewed.
  • Use encrypted or access-controlled sharing when proof material is sensitive.
  • Flag any special handling requirements clearly in the email.

Permissions and integrations should be explainable.

Local-first behavior is preferred where it fits the feature, and public security/privacy language should stay tied to what the shipped product actually does.