Skip to content

Security: volta-npo/local-schema-forge

Security

SECURITY.md

Security Policy: Local Schema Forge

Data handled

This local-first product may contain customer and owner business data. Data stays in the browser unless a user exports it.

Product-specific risks

  • Do not enter raw passwords, API keys, bank credentials, private keys, or regulated sensitive data.
  • Treat exported JSON/CSV/Markdown as client records and store them in approved Volta project folders.
  • Verify evidence before using any generated packet for owners, sponsors, funders, or public reporting.
  • For this product's domain, review these gates before handoff: Generated JSON must parse, Required fields by type, Opening hours format enforced.

Reporting

Report vulnerabilities privately to Volta maintainers before public disclosure.

There aren't any published security advisories