Skip to content

Security: cloud7-dev/screenshot-evidence-kit

Security

SECURITY.md

Security Policy

Screenshot Evidence Kit handles sensitive local evidence. Please report security issues privately before public disclosure.

Supported Scope

The public core includes:

  • static browser app behavior,
  • manifest schema,
  • local hashing and verification,
  • redaction metadata,
  • sample packet fixtures,
  • CLI verifier.

The public core does not include hosted evidence storage, lawyer matching, payments, or SaaS dashboards.

Reporting

For now, open a GitHub issue with a minimal non-sensitive reproduction and mark it clearly as a security concern. Do not attach real dispute screenshots, personal information, addresses, phone numbers, account numbers, or private legal materials.

Privacy Rules For Reports

  • Use dummy screenshots.
  • Replace personal information with synthetic values.
  • Do not upload original evidence.
  • Describe the risk in terms of integrity, redaction leakage, manifest verification, or local file handling.

Non-Guarantees

This project does not provide legal advice, forensic certification, or evidence admissibility guarantees.

There aren't any published security advisories