Skip to content

Security: SubhamSathua/keyweave

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

If you find a security vulnerability, please DO NOT open a public issue. Publicly disclosing a vulnerability can put users at risk.

Instead, please report security vulnerabilities through one of the following methods:

  1. GitHub Security Advisories: Report a vulnerability
  2. Direct Contact: Reach out via GitHub Issues with the "security" label.

We will acknowledge your report and attempt to fix the issue as soon as possible.

Distribution & Malware Disclaimer

The author of this project only provides source code and official releases through authorized channels (e.g., this GitHub repository).

  • Official Builds: Only releases published directly by the original maintainer are official "KeyWeave" products.
  • Third-Party Distributions: We are not responsible for versions of this software downloaded from other websites, forums, or third-party collections.
  • Modified Versions: If you download a version that has been modified by someone else, you do so at your own risk.

Limitation of Liability

As stated in the MIT License: In no event shall the author be liable for any claim, damages, or other liability, whether in an action of contract, tort, or otherwise, arising from, out of, or in connection with the software or the use or other dealings in the software.

Security Best Practices

When using KeyWeave, keep the following in mind:

  • Local Only: KeyWeave runs entirely in your browser. No data is sent to external servers.
  • No Sensitive Data: The app generates typing drills — do not input or store sensitive information.
  • Trusted Sources: Only download KeyWeave from the official GitHub repository.

Last updated: July 14, 2026

There aren't any published security advisories