Please report suspected vulnerabilities privately to
info@splidly.site. Include the affected component,
reproduction steps, and potential impact. Do not include real user data or
credentials.
Please allow a reasonable period for investigation and remediation before any public disclosure. Security reports will be acknowledged as soon as practical, and material confirmed issues will receive status updates through the reporting address.
Security fixes are applied to the current production release and the default branch. Older self-hosted revisions are not maintained; self-hosters should upgrade to the latest release and rebuild pinned container images regularly.
The Splidly server, mobile applications, authentication and invitation flows, and official deployment configuration are in scope. Social-login providers, app stores, operating systems, and independently operated Splidly deployments are outside the project's control and should be reported to their operators.