Only the latest released version of MarketMind receives security updates. Always run the most recent release.
| Version | Supported |
|---|---|
| Latest | ✅ |
| Older | ❌ |
Please do not open a public GitHub issue for security reports.
Email security reports privately to nathansilvasantos@gmail.com with:
- A clear description of the issue.
- Steps to reproduce, including the affected version (see the version badge in the README).
- Impact assessment and any suggested fix, if you have one.
- Whether the issue is already public anywhere.
You should receive an acknowledgement within 3 business days. A fix and coordinated disclosure timeline are discussed case-by-case based on severity.
In scope: the MarketMind desktop app, the bundled backend (apps/backend), and the shared @marketmind/* packages in this repository.
Out of scope: third-party services (Binance, Interactive Brokers), the user's local machine outside the app sandbox, social-engineering scenarios.
We will not pursue legal action against researchers who:
- Make a good-faith effort to avoid privacy violations, data destruction, or service disruption.
- Only access the minimum amount of data necessary to demonstrate the issue.
- Give us a reasonable window to fix the issue before public disclosure.
Thank you for helping keep MarketMind users safe.