| Version | Supported |
|---|---|
| 1.x.x | ✅ |
| < 1.0 | ❌ |
If you discover a security vulnerability, please DO NOT create a public issue.
Instead, please email: [email protected]
Include:
- Detailed description of the vulnerability
- Steps to reproduce
- Potential impact
- Suggested fix (if any)
You will receive acknowledgment within 48 hours.
Caution
EchoVault syncs your AI chat history to cloud storage. This data may contain:
- Code snippets and file paths
- API keys or secrets mentioned in conversations
- Personal information
Recommendations:
- Review chat history for sensitive data before enabling sync
- Use a private cloud storage account
- Encryption feature coming in v2.0
- Rclone credentials stored via OS keyring
- Local SQLite database (not exposed)
- No telemetry or data collection
- Regular dependency updates via Dependabot