Skip to content

Security: axfrgo/dropply

Security

SECURITY.md

Security Policy

Scope

Dropply is a local-first desktop application with open-core positioning.

This repository currently covers:

  • desktop app code
  • local storage behavior
  • packaging configuration
  • relay foundation

Supported version

  • 1.x

Reporting

Until a dedicated security inbox exists, security issues should be handled privately and not disclosed in public issues.

Current baseline controls

  • scoped asset protocol access
  • packaged CSP restrictions
  • local-first storage defaults
  • no mandatory account dependency for desktop core

Planned improvements

  • optional local encryption
  • end-to-end encryption for sync payloads
  • signed update and release verification guidance
  • hosted-tier auth and secret-management policy

There aren’t any published security advisories