Sidecar performs calculations, file transforms, and workspace encryption in browser. It has no server, account system, analytics, or data-upload endpoint.
Use GitHub private vulnerability reporting when available. Do not open public exploit details involving workspace import, cryptography, file processing, or service-worker integrity.
Include affected version, browser, reproduction, and impact. Never include real workspace exports, passphrases, safety cards, or personal images.
Regular workspace data uses browser localStorage. No Sidecar operator receives it, but another person or malicious software with access to same browser profile can read it. Encrypted .sidecar exports use PBKDF2-SHA-256 and AES-256-GCM; security depends on passphrase strength.
Safety-card data uses separate localStorage record and is excluded from regular history and workspace exports.