Skip to content

Security: larai-w/microduck

Security

SECURITY.md

Security Policy

This policy applies to all public repositories under github.com/larai-w and the VEAI LAB. websites (veai.jp, veai-projects.com, hire-veai.com).

Reporting a Vulnerability

If you believe you have found a security vulnerability, please report it privately — do not open a public issue.

  • Email: security@veai.jp
  • Or use GitHub's private "Report a vulnerability" form on the affected repository, if enabled.

Please include, where possible:

  • The repository (or site URL) and version/commit affected
  • A description of the issue and its potential impact
  • Steps to reproduce, or a proof of concept

What to Expect

  • We aim to acknowledge reports within 7 days. VEAI LAB. is a small research lab, so please bear with us on complex issues.
  • We will keep you informed while we investigate, and let you know when a fix or mitigation ships.
  • With your permission, we are happy to credit you in the release notes.
  • There is currently no bug bounty program; reports are handled on a best-effort basis.

Out of Scope

  • Findings that require physical access to a user's device
  • Vulnerabilities in third-party services we do not operate (please report those upstream)
  • Automated scanner output without a demonstrated impact

Thank you for helping keep caregivers' data safe.

There aren't any published security advisories