WaveLink handles live Salesforce sessions and customer data workflows, so security reports are taken seriously and handled with priority.
Only the latest release published on the Chrome Web Store and the current
main branch receive security fixes.
Please do not open a public issue for anything you believe is exploitable.
- Preferred: open a private security advisory — Report a vulnerability.
- If that is not possible, open a GitHub issue with the
securitylabel and omit exploit details; a maintainer will follow up privately.
Please include a description, reproduction steps, potential impact, and a suggested fix if you have one. We aim to acknowledge reports within 48 hours and to ship a fix for confirmed issues within 30 days.
- WaveLink is local-first: it makes network requests only to the Salesforce orgs the user connects. Anything that causes data or credentials to leave the device otherwise is in scope and high priority.
- The full security architecture, data inventory, and threat model are
documented in
docs/SECURITY.md. Known, publicly tracked security work is labelledsecurityon the issue tracker.