OpenScene does not currently have a private vulnerability-reporting channel configured.
Until one is available, do not open a public GitHub issue or pull request containing secrets, private media, personal data, exploit steps, proof-of-concept code, or other material that could enable abuse.
If you discover a potential vulnerability, limit public discussion to a non-sensitive request for a private reporting route. Do not include technical details. Maintainers will publish a private contact method or GitHub security advisory workflow when one is configured.
OpenScene is a local-first desktop application. Reports involving Electron security boundaries, preload/IPC exposure, local file handling, FFmpeg invocation, bundled dependencies, or accidental network behavior are in scope.
Do not test against systems, accounts, files, or media you do not own or have explicit permission to assess. Do not publish credentials, tokens, private file paths, user recordings, voice samples, or exploit material.
Security fixes are assessed against the latest code on dev and released versions on main. This policy does not promise a response time or a private reporting channel until one is configured.