Skip to content

Security policy

Public security discussion

Public issues and comments are welcome for general security concerns, defence-in-depth suggestions, threat-model discussions, and vulnerabilities that have already been disclosed.

If a report describes a previously undisclosed vulnerability that could enable exploitation, contributors are encouraged to report the sensitive details privately through GitHub Security Advisories for epicecu/table, or by email to David Cedar at david@epicecu.com. A public issue may still identify the general concern, provided it does not include exploit instructions, credentials, keys, private device payloads, or real vehicle information.

Private reports should include affected versions, a minimal reproduction, and any known impact. Security fixes and relevant technical details may be discussed publicly after the issue has been assessed and sensitive risks have been addressed.

Released under the MIT Licence.