Please report security issues privately — do not open a public issue for a suspected vulnerability.
- Email: security@vornik.io with details and, if possible, a minimal reproduction.
- You'll receive an acknowledgement; we'll coordinate a fix and disclosure timeline with you.
Before public release: the
security@vornik.ioinbox is provisioned and a PGP key is published here (for encrypted reports) ahead of the public flip.
Security fixes target the latest released line. Once a versioning and release cadence is published (with the first public release), this section lists exactly which lines receive fixes.
This policy covers the Vornik Community Edition in this repository. The Enterprise overlay is covered separately under its commercial terms.