Skip to content

Security: Deathcharge/samsarix-story-studio

SECURITY.md

Security policy

Supported code

Security fixes target the latest release and the current default branch. Older commits, experimental branches, private deployments, modified distributions, and unsupported hosted configurations may not receive patches.

Samsarix Story Studio is designed for one trusted desktop user and loopback-only access. Internet-facing or multi-user deployment is outside the supported security model.

Report a vulnerability

Email support@samsarix.com with the subject Security: Samsarix Story Studio. Please do not open a public issue for an unpatched vulnerability.

Include, when available:

  • the affected commit or version;
  • the prerequisites and impact;
  • minimal reproduction steps or a proof of concept;
  • relevant logs with credentials and private story content removed;
  • whether you believe the issue is already public.

Do not access other people's data, incur provider charges, disrupt services, or retain secrets while researching. The maintainers aim to acknowledge a complete report within five business days and will coordinate validation, remediation, and disclosure in good faith. This is a response target, not a contractual service-level agreement or bug-bounty promise.

General support belongs at the same address without the security subject prefix. Licensing and business inquiries belong at contact@samsarix.com.

There aren't any published security advisories