"oAI" reads as easily confused with OpenAI, both visually and in casual conversation. Renamed to "Confab" throughout: Xcode target/scheme/bundle ID (com.oai.Confab), Info.plist and Help Book identity, all user-facing UI text, internal Log subsystem and color identifiers, localization catalogs (6 languages, including a proper reworded/retranslated Intel-deprecation notice), Help Book HTML content, and docs (README/DEVELOPMENT/PRIVACY/SECURITY). Deliberately cosmetic-only: the on-disk data folder (~/Library/Application Support/oAI/), database/backup filenames, Keychain service identifiers, and EncryptionService's key-derivation inputs are all left untouched so existing conversations, settings, and stored API keys survive the update with zero migration and no re-entering credentials. Verified live: a real signed build successfully decrypted a stored API key and loaded an existing conversation database after the bundle ID change. Also includes a small already-completed, previously uncommitted model-release-date feature (ModelInfo/OpenRouterModels/ OpenRouterProvider/ModelInfoView) that happened to share several files with this rename. Gitignored on this branch and updated on disk but not part of this commit: CLAUDE.md, RELEASE_NOTES.md, and the build*.sh scripts.
30 lines
1.3 KiB
Markdown
30 lines
1.3 KiB
Markdown
# Security Policy
|
|
|
|
## Supported Versions
|
|
|
|
Only the latest publicly released version of Confab is supported with security fixes. Please update to the latest version before reporting an issue, and confirm it still reproduces there.
|
|
|
|
## Reporting a Vulnerability
|
|
|
|
If you discover a security vulnerability in Confab, please report it privately rather than opening a public GitHub issue.
|
|
|
|
To report a security concern, use the contact form at **[https://oai.pm/#contact](https://oai.pm/#contact)**.
|
|
|
|
Please include as much detail as possible:
|
|
- A description of the vulnerability and its potential impact
|
|
- Steps to reproduce the issue
|
|
- The Confab version and macOS version you're using
|
|
- Any relevant logs (`~/Library/Logs/Confab.log`), with sensitive data redacted
|
|
|
|
## Scope
|
|
|
|
Confab is a native macOS app that stores conversations, settings, and API keys locally (SQLite database and Keychain). Areas of particular interest for security reports include:
|
|
- API key handling and Keychain storage
|
|
- MCP file access permission checks
|
|
- Bash execution approval flow
|
|
- Any path that could lead to data exfiltration or unauthorized local file/system access
|
|
|
|
## Response
|
|
|
|
Reports submitted through the contact form will be reviewed and acknowledged as soon as possible. Please allow time for a fix to be developed and released before any public disclosure.
|