AetherAssembly
  • Apps
  • Wiki
  • About
  • GitHub
  • Contribute
AetherAssembly

Security Policy

Last updated: 2026-06-25

This policy covers all AetherAssembly projects. We take security reports seriously and will act on them as quickly as we can. This page explains how to reach us, what to expect from us, and how we handle things from receipt through to fix and disclosure.

How to report

Please do not disclose vulnerabilities in public issues, pull requests, or comment threads. Use GitHub private vulnerability reporting on the relevant repository if it is enabled, or contact us directly through one of the following:

  • Email: support@aetherassembly.org
  • Contact form: forms.gle/T4i7GGzaT3HUrffm9
  • Aster directly (GitHub): @Aster1630

To help us triage quickly, include: a clear description of the issue, steps to reproduce it, your assessment of the impact, and any suggested fix or workaround if you have one. We don't require a CVE or a formal writeup — plain language is fine.


What happens after you report

We aim to acknowledge every report within 7 days. From there, here is roughly what the process looks like:

  1. Triage: We reproduce the issue and assess severity. If we can't reproduce it or need more information, we'll follow up and ask.
  2. Fix: We work on a patch. For critical issues we prioritise this above everything else. For lower-severity issues it goes into the normal development queue, but we'll keep you updated on timing.
  3. Release: The fix ships as part of the next release, or as a dedicated patch release for anything serious.
  4. Disclosure: Once the fix is out, we'll coordinate with you on a disclosure timeline. We default to public disclosure within 90 days of the initial report, or sooner if both parties agree. We'll credit you in the release notes and any public advisory unless you'd prefer to stay anonymous.

Supported versions

Security patches are applied to the current release and the two most recent releases of each project. Older versions are not actively patched. If you're on an older version, updating to the latest release is always the safest option.


What's in scope

We're most interested in issues that could realistically affect users: things like data exposure, privilege escalation, unsafe handling of user input, insecure IPC or storage patterns, or supply chain risks in our dependencies. All three projects are in scope: Attyre, Before It's Gone, and MindTab.

What's out of scope

The following are generally not treated as security issues: theoretical vulnerabilities without a working proof of concept, issues that require physical access to an already-compromised device, social engineering, self-XSS, missing security headers on pages that don't handle sensitive data, and reports generated by automated scanners without manual verification. General bugs and feature requests belong in the normal issue tracker on GitHub or the GitLab mirror.

AetherAssembly
  • Apps
  • Wiki
  • About
  • Security
  • Terms
  • Privacy
  • GitHub