# Security policy ## Reporting a vulnerability Please do **not** report security vulnerabilities in public issues, discussions, pull requests, screenshots, or social-media posts. Email [nomily@geekis.com](mailto:nomily@geekis.com) with the subject `[Security] Nomily`. Include a concise description, affected repository and commit, reproduction steps using non-sensitive data, and the impact you observed. Do not send API keys, recordings, transcripts, device identifiers, account information, customer data, private endpoints, firmware, or vendor documents. If a proof of concept would expose those materials, describe the minimum safe steps instead. ## Scope Security reports concerning the public Nomily repositories are welcome, including credential handling, local storage, network requests, permissions, cryptography, and BLE protocol handling. Product compatibility and ordinary feature requests should be filed as normal issues in the affected repository. ## Response This is a small-team project, not a 24/7 security operations centre. We will acknowledge a valid report as soon as practical, assess its scope, and keep the reporter informed when a fix or coordinated disclosure is appropriate.