Please report security vulnerabilities privately.
Email: security@contextfort.ai GitHub: Use Private Vulnerability Reporting
Do NOT open public issues for security vulnerabilities.
- Description of the vulnerability
- Steps to reproduce
- Potential impact
- Suggested fix (if any)
- Initial Response: Within 48 hours
- Status Update: Within 5 business days
- Fix Timeline: Based on severity
- Critical: 1-3 days
- High: 1 week
- Medium: 2 weeks
- Low: 1 month
| Version | Supported |
|---|---|
| 1.0.x | ✅ Yes |
| < 1.0 | ❌ No |
- Vulnerability Reported - Via email or private GitHub report
- Assessment - Security team evaluates severity and impact
- Fix Development - Patch developed and tested
- Release - Security update pushed to Chrome Web Store
- Disclosure - Public disclosure after fix is deployed (coordinated disclosure)
- Local Storage Only - No data transmitted to external servers
- No Cloud Dependencies - All processing happens in-browser
- Content Security Policy - Strict CSP prevents XSS attacks
- Permissions - Minimal required permissions
- Open Source - Full code audit available
- Screenshots: Stored locally in Chrome storage, encrypted at rest by Chrome
- Sessions: Stored locally, no transmission to external servers
- Rules: Stored locally in Chrome storage
- Analytics: Optional PostHog (can be disabled with one line change)
posthog-js- Analytics (optional, can be disabled)
- Automated dependency scanning via GitHub Dependabot
- Regular security audits of dependencies
- Prompt updates for known vulnerabilities
- GDPR: Data processing happens locally, no data transmission
- CCPA: No sale of personal information
- SOC2: In progress (Q2 2025)
- ISO 27001: Planned (Q3 2025)
- Protected main branch
- Pull request reviews required
- Automated security scanning
- Signed commits recommended
- Manifest V3 compliance
- No eval() or inline scripts
- Strict Content Security Policy
- Chrome Web Store security review (pending)
For security concerns:
- Email: security@contextfort.ai
- GitHub: @ContextFort-AI
For general questions, see README.md.