Skip to content

Security: Clyvora/Convert

Security

SECURITY.md

Security policy

Supported version

Clyvora Convert is public beta software. Security fixes are applied to the latest code on main; no stable release is supported yet.

Report privately

Email security@clyvora.tech or use GitHub private vulnerability reporting. Do not publish exploit details in an issue. Use synthetic media and include the affected browser, reproduction steps, impact, and any suggested mitigation.

We aim to acknowledge reports within five business days, provide a severity assessment after initial reproduction, and coordinate a fix before public disclosure. A 90-day disclosure window is the default, but it may be shortened for active exploitation or extended by mutual agreement.

Severity is based on impact and exploitability: Critical means practical compromise of file confidentiality or arbitrary code execution; High means significant unauthorized access or persistent compromise; Medium means limited security or privacy impact requiring specific conditions; Low means defense-in-depth or minor information exposure.

There aren't any published security advisories