ClambHook is a VPN and proxy router with opt-in HTTP(S) capture, so security reports are taken seriously and handled privately.
Report suspected vulnerabilities privately by email to support@swiphtgroup.com.
- Do not open a public GitHub issue for a security problem.
- Include the affected component (C17 daemon or command-line client, SwiftUI app/helper, JavaFX/Gluon app, or Kotlin Android service), version or commit, platform, reproduction steps, and impact.
- If you have a proof of concept, attach or describe it; do not post it publicly.
You will receive an acknowledgement, and coordinated disclosure will be arranged before any public description of the issue. Please allow a reasonable remediation window before disclosing details elsewhere.
The supported surfaces are the macOS, GNU/Linux, and Android public releases; the shared C17 runtime and control/event contracts; the SwiftUI and JavaFX/Gluon clients; the Kotlin Android platform bridge; packaging; and the release/update/licensing pipeline.
This reporting policy supplements the rights granted by LICENSE
and LICENSING.md; it does not reduce those rights or authorize
testing against systems or traffic you do not own or have permission to test.