| Component | Supported | Notes |
|---|---|---|
| notiky-cli | Latest release | Apache 2.0 |
| Hosted Notiky (notiky.com) | Active | Managed by Notiky team |
This repo (.github) |
Active | Marketing/docs only — no runtime code |
If you discover a security vulnerability in Notiky:
- Do not open a public GitHub issue
- Email security@notiky.com with:
- Description of the vulnerability
- Steps to reproduce
- Impact assessment (if known)
- Your contact information
We aim to acknowledge reports within 48 hours and provide a status update within 7 days.
In scope:
- notiky-cli (installation, daemon, MCP server)
- Hosted Notiky web application and API (notiky.com)
- Authentication and authorization flows
- MCP token handling
Out of scope:
- Social engineering attacks
- Denial of service against notiky.com infrastructure
- Issues in third-party dependencies without a demonstrable Notiky-specific impact
- Content in this marketing repository that does not affect product security
We follow coordinated disclosure. Please allow reasonable time for a fix before public disclosure. We will credit researchers who report valid vulnerabilities (with permission).