Skip to content

Security: Endokelp/NextStep

Security

SECURITY.md

Security Policy

Reporting a vulnerability

Report security issues privately through GitHub Security Advisories rather than opening a public issue.

Please include what you found, how to reproduce it, and what an attacker could do with it. Expect a first response within a week. This is a volunteer project, so please be patient.

Threat model

NextStep's architecture removes most of the usual attack surface:

  • No backend server. The site is static files. There is no API to attack, no server-side session, and no admin credential to steal.
  • No central database. User data lives in the user's own browser storage or in a file on their disk. There is no shared datastore to breach, and a compromise of one user never exposes another.
  • No stored API keys. The user's model provider key is held in their browser and sent only to that provider. It never reaches a NextStep server, because there isn't one.

What that leaves worth reporting:

  • Anything that causes a user's API key to be transmitted somewhere other than their chosen provider
  • Cross-site scripting, especially in Compass output or any user-supplied text that gets rendered
  • Anything that lets one browser origin read another origin's IndexedDB document
  • Supply-chain issues in our dependencies that reach the browser

Dossier sharing is print-to-PDF in the browser. There are no share links and no tokens to revoke.

For self-hosters

If you deploy your own instance, you inherit responsibility for it. Serve over HTTPS, keep dependencies patched, and if you modify the app to add a backend, understand that you have re-introduced the threat surface this design removes — and that AGPL-3.0 requires you to publish those modifications.

There aren't any published security advisories