Skip to content

Security: Szujo-Janos/Aptoria

SECURITY.md

Security Policy

Supported version

Version Status
2.1.9 Current public portable package

Security fixes are handled on the current public package line unless a separate agreement states otherwise.

Report security issues privately

Please report security issues privately to the project maintainer.

Do not publish exploit details, customer data, active credentials, private signing keys, license registry data or production configuration in public issues.

Sensitive files that must not be published

Do not commit or distribute runtime secrets, generated local state, customer data or production license authority material.

.env
database/database.sqlite
storage/app/aptoria-license.json
storage/app/license-public.pem
storage/app/license-private.pem
storage/app/license-authority-private.pem
storage/app/license-authority-registry.json
storage/app/license-runtime-lease.json
storage/app/license-install-id
storage/app/runtime/*
storage/app/installed.lock
storage/app/setup-token.txt
storage/logs/*
storage/framework/cache/*
storage/framework/sessions/*
storage/framework/views/*
bootstrap/cache/*.php
license-issuer/config.php
license-issuer/storage/*.json
license-issuer/storage/*.jsonl
license-issuer/storage/*.pem
license-issuer/storage/*.zip
generated reports
generated decision packages
customer evidence files

Public keys and build manifests

Official portable packages may include public keys and signed build manifests used for package verification.

These files are not private secrets, but they are part of the official build chain. Do not edit them manually, and do not replace them with local test material in public packages.

Private signing keys must never be published.

License and runtime controls

Do not bypass, remove, weaken or misrepresent Aptoria license, activation, runtime lease, build-integrity, audit or security controls.

Security research is welcome when it is reported responsibly and does not include public release of active bypass instructions or production secrets.

There aren't any published security advisories