Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
This PR adds a `SECURITY.md` file to the repository, providing a clear security policy for the Quiet project. The document outlines: - The scope and limitations of Quiet’s current security posture. - Supported versions, with the latest release being the only one to receive timely patches. - Guidance on iOS push notifications, noting potential metadata exposure, and the option for users to disable them for better privacy. - Warnings that Quiet is not audited and is unsuitable for high-risk scenarios where proven security is required. - A vulnerability reporting process, with details on disclosure timelines and crediting reporters. - References to the project’s Threat Model and future intentions to refine metadata exposure details. This addition aims to improve transparency and help users understand Quiet’s current security stance and who should or shouldn’t rely on it. Feedback is welcome, especially regarding clarity and completeness.
- Loading branch information