MindForge is a local-first encrypted memory system — security is core to the project.
If you discover a security vulnerability, please report it responsibly:
- Email: 2638895480@qq.com
- Subject line:
[SECURITY] MindForge — <brief description> - Include: steps to reproduce, affected version, potential impact
| Stage | Target |
|---|---|
| Acknowledgment | 48 hours |
| Initial assessment | 7 days |
| Fix or mitigation | 30 days (severity-dependent) |
- Encryption implementation (AES-256-GCM, PBKDF2-SHA256)
- API authentication and rate limiting
- MCP tool parameter validation
- Local storage and database access
- Third-party dependencies (report upstream)
- Social engineering attacks
We follow coordinated disclosure. Please do not publish details publicly until a fix is released.