Files
tab-bot/SECURITY.md
T
2026-09-06 19:28:26 -04:00

10 lines
614 B
Markdown
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
# Security
Report TabBot vulnerabilities to **[email protected]**. Do not attach bot tokens, vault passphrases, or named-secret values.
TabBot does not hold user tokens on HoneyPeer servers. The official origin is https://tab-bot.rest; vault ciphertext still lives in the visitors browser. Typical issues are XSS on a TabBot origin, unsafe module import, or documentation that leaks secrets.
See `legal/security.md` (also `/legal/security`) and `docs/security/threat-model.md`. Incident handling is in the legal Security page.
Hangout: https://join.discord-linux.com — still do not paste secrets there.