Security IS the product. Any vulnerability here is critical.
Report ONLY via GitHub Security Advisories. NEVER open a public issue. Response within 24h.
- Encryption implementation (client-side E2E)
- Key management and storage
- Self-destruct mechanism bypass
- Server-side plaintext exposure
- WebSocket session hijacking
- Authentication bypass