| Version | Supported |
|---|---|
| Latest | ✅ |
empathySync takes security seriously, especially given our focus on user wellbeing and safety-critical features.
If you discover a vulnerability in:
- Crisis detection (bypasses that could miss suicidal ideation)
- Harmful content blocking (ways to extract dangerous information)
- Data privacy (unintended data transmission or exposure)
Please report these privately by opening a private security advisory on GitHub.
Do NOT open a public issue for security vulnerabilities.
- Description of the vulnerability
- Steps to reproduce
- Potential impact
- Suggested fix (if you have one)
- Acknowledgment: Within 48 hours
- Initial assessment: Within 1 week
- Fix timeline: Depends on severity, but safety-critical issues are highest priority
- Bypasses of safety systems (crisis, harmful content)
- Data exposure (conversations, wellness data)
- Code injection vulnerabilities
- Denial of service affecting safety features
- Issues with Ollama itself (report to Ollama)
- Theoretical attacks requiring physical access
- Social engineering attacks
- Issues already documented as limitations
Our security model prioritizes:
- User safety first - Crisis detection must never fail silently
- Privacy by design - Data stays local by default
- Fail safe - When uncertain, err on the side of caution
Thank you for helping keep empathySync safe for everyone.