Security fixes target the latest version on the main branch.
Do not open a public issue for a suspected vulnerability. Send the affected version, reproduction steps, and impact to contact@jesed.dev. Do not include real credentials, private keys, or sensitive files.
We will acknowledge the report, investigate it privately, and coordinate a fix and disclosure where appropriate.
Qarmor processes selected files locally in the browser and does not upload them to a Qarmor service. It cannot protect against a compromised browser, malicious extension, malware, screen capture, unsafe backups, or loss of the decryption key or passphrase.
The v3 file header is public but authenticated. The filename is encrypted with the payload. Passphrase, image, and SSH-key modes inherit the entropy and secrecy of their input; only recipient-key mode uses ML-KEM-1024. Qarmor has not been formally verified or independently audited.