Report security issues privately through GitHub Security Advisories rather than opening a public issue.
Please include what you found, how to reproduce it, and what an attacker could do with it. Expect a first response within a week. This is a volunteer project, so please be patient.
NextStep's architecture removes most of the usual attack surface:
- No backend server. The site is static files. There is no API to attack, no server-side session, and no admin credential to steal.
- No central database. User data lives in the user's own browser storage or in a file on their disk. There is no shared datastore to breach, and a compromise of one user never exposes another.
- No stored API keys. The user's model provider key is held in their browser and sent only to that provider. It never reaches a NextStep server, because there isn't one.
What that leaves worth reporting:
- Anything that causes a user's API key to be transmitted somewhere other than their chosen provider
- Cross-site scripting, especially in Compass output or any user-supplied text that gets rendered
- Anything that lets one browser origin read another origin's IndexedDB document
- Supply-chain issues in our dependencies that reach the browser
Dossier sharing is print-to-PDF in the browser. There are no share links and no tokens to revoke.
If you deploy your own instance, you inherit responsibility for it. Serve over HTTPS, keep dependencies patched, and if you modify the app to add a backend, understand that you have re-introduced the threat surface this design removes — and that AGPL-3.0 requires you to publish those modifications.