Report suspected vulnerabilities privately by emailing security@clyvora.tech or using private vulnerability reporting in the affected Clyvora repository. Do not include exploit details or private files in a public issue.
We aim to acknowledge reports within five business days, assess severity after reproduction, and coordinate a fix before disclosure. A 90-day disclosure window is the default, with adjustments for active exploitation or by mutual agreement.
Critical issues include practical compromise of selected-file confidentiality or arbitrary code execution. High issues cause significant unauthorized access or persistent compromise. Medium issues have limited impact or require special conditions. Low issues are defense-in-depth concerns.