TheThe0.5.0
The/Security

Found a vulnerability? Write to us.

The editor runs locally and handles other people's files, so vulnerabilities in format parsing and in plugins are a priority for us. We accept reports at any stage.

how to report

Contact and what to attach.

address
security@ — to be confirmed
response
acknowledgement of receipt — target time to be confirmed
language
English or Russian
  • Build version and operating system
  • Reproduction steps and, if possible, a sample file
  • Which component is affected: core, format plugin, integration
  • Your disclosure terms, if you have any

placeholder

The reporting address, target response times and the disclosure policy are not fixed in the project materials. They must be approved before publication: a security page without a working contact is worse than none.

what protects your data

Guarantees built into the core.

Atomic saving

The file is replaced whole: a crash or power cut during a write leaves no damaged document.

Cross-process locking

An open file will not be silently overwritten by a second editor process.

External-change control

If the file changed on disk, the editor says so and leaves the choice to you.

Local operation

No cloud and no mandatory account: file contents never leave the device.

third-party components

We know what we are built from.

The uses external libraries — Qt, tree-sitter, RE2, libgit2 and others. Their list, versions and licences are published and available without registration; that is also what the LGPLv3 and GPLv3 licences require.

NoticesThe full list of third-party components and their licencesno JS
LGPLLGPLv3 compliance: sources and library replacement termsrequired
PrivacyWhat is collected, what is not, and how it is storeden · ru

for regulatory work

If the product is distributed in the EU, this page becomes the entry point for EU CRA requirements: a reporting channel, coordinated disclosure and a support period per version. The wording must be cleared legally, not written by analogy.