Skip to content

Security: nathanssantos/marketmind

Security

SECURITY.md

Security Policy

Supported Versions

Only the latest released version of MarketMind receives security updates. Always run the most recent release.

Version Supported
Latest ✅
Older ❌

Reporting a Vulnerability

Please do not open a public GitHub issue for security reports.

Email security reports privately to nathansilvasantos@gmail.com with:

  • A clear description of the issue.
  • Steps to reproduce, including the affected version (see the version badge in the README).
  • Impact assessment and any suggested fix, if you have one.
  • Whether the issue is already public anywhere.

You should receive an acknowledgement within 3 business days. A fix and coordinated disclosure timeline are discussed case-by-case based on severity.

Scope

In scope: the MarketMind desktop app, the bundled backend (apps/backend), and the shared @marketmind/* packages in this repository.

Out of scope: third-party services (Binance, Interactive Brokers), the user's local machine outside the app sandbox, social-engineering scenarios.

Safe Harbor

We will not pursue legal action against researchers who:

  • Make a good-faith effort to avoid privacy violations, data destruction, or service disruption.
  • Only access the minimum amount of data necessary to demonstrate the issue.
  • Give us a reasonable window to fix the issue before public disclosure.

Thank you for helping keep MarketMind users safe.

There aren't any published security advisories