# Security Policy ## Supported Versions Only the latest publicly released version of oAI is supported with security fixes. Please update to the latest version before reporting an issue, and confirm it still reproduces there. ## Reporting a Vulnerability If you discover a security vulnerability in oAI, please report it privately rather than opening a public GitHub issue. To report a security concern, use the contact form at **[https://oai.pm/#contact](https://oai.pm/#contact)**. Please include as much detail as possible: - A description of the vulnerability and its potential impact - Steps to reproduce the issue - The oAI version and macOS version you're using - Any relevant logs (`~/Library/Logs/oAI.log`), with sensitive data redacted ## Scope oAI is a native macOS app that stores conversations, settings, and API keys locally (SQLite database and Keychain). Areas of particular interest for security reports include: - API key handling and Keychain storage - MCP file access permission checks - Bash execution approval flow - Any path that could lead to data exfiltration or unauthorized local file/system access ## Response Reports submitted through the contact form will be reviewed and acknowledged as soon as possible. Please allow time for a fix to be developed and released before any public disclosure.