Betar is pre-alpha and has not had an independent security audit. Treat it accordingly — don't rely on it for anything where a real vulnerability would put you at risk.
Please report security issues privately rather than opening a public issue. Open a GitHub security advisory for this repo, or contact work.konkomaji@gmail.com directly.
Include what you found, how to reproduce it, and its impact if you can. We'll acknowledge reports as quickly as we can given this is a small, pre-alpha project.
This covers the Betar Android app itself. Protocol- or cryptography-level
vulnerabilities in the underlying mesh engine belong to
Project Mesh — report there if the issue
is in core/, not the app.