Telepathy welcomes good-faith security reports. For its privacy and security model, see PRIVACY.md.
The latest stable release and current master branch receive security fixes; older releases, forks, and unofficial builds may not.
Do not report suspected vulnerabilities in a public issue, discussion, or pull request. Email me@chanchan.dev with the subject Telepathy security report. Include the likely impact, affected version and platform, and clear reproduction steps or a proof of concept where practical. Remove private keys, message contents, attachments, and other sensitive data unless they are essential to the report.
Reports will be investigated and fixes or mitigations released when appropriate. Please allow a reasonable opportunity to address an issue before publishing details. Response times are not guaranteed, and Telepathy does not currently offer a bug bounty. Test only systems and data you own or are authorized to use; report issues that exist entirely in a dependency to that project's maintainers as well.