Security fixes are provided for the current development branch and the latest released version line.
If you believe you have found a security issue in Illustia, please report it privately instead of opening a public issue.
This repository does not publish a dedicated security contact address. Use the project's preferred private reporting channel, or ask a maintainer for the current security contact before sharing sensitive details.
Include as much detail as possible:
- A short summary of the issue
- The affected version or commit, if known
- Steps to reproduce
- The expected and actual behavior
- Any logs, screenshots, or proof of concept material
Do not post vulnerability details publicly until maintainers have had a chance to review and respond.
After a report is received:
- We will acknowledge receipt.
- We will review and validate the report.
- We will work on a fix or mitigation if the issue is confirmed.
- We will coordinate disclosure timing with the reporter when practical.
This policy covers the Illustia Android application and related repository assets.
If your report concerns third-party services or dependencies used by the app, include the dependency name and version when available.