Do not report security vulnerabilities through public GitHub issues, Discord channels, or other public project spaces.
Report suspected vulnerabilities privately by emailing tailtag@proton.me.
Include, where possible:
- The affected component
- Steps to reproduce the issue
- The potential impact
- Any relevant screenshots, logs, or proof-of-concept details
- Whether you believe the issue is being actively exploited
The TailTag maintainers will acknowledge the report, investigate it, and coordinate disclosure or remediation as appropriate.
TailTag is currently under active redevelopment and does not yet have a supported production release. This policy will be updated before public beta testing.