Skip to content
Liberated Bread

Security Policy

We take security seriously — for our infrastructure, for the devices we document, and for the people who follow our guides. If you've found a security issue, we want to hear about it.

Responsible Disclosure

Please report security vulnerabilities privately, not in a public GitHub issue. We follow a coordinated disclosure process:

  1. Email us at the address below with a description of the issue
  2. We'll acknowledge your report within 72 hours and provide an estimated timeline for a fix
  3. We'll keep you updated as we work on the issue
  4. Once a fix is ready, we'll coordinate a public disclosure date with you
  5. We'll credit you in the disclosure (unless you prefer to remain anonymous)

Please don't:

Scope

The following are in scope for security reports:

The following are out of scope:

Contact

Email for security reports: security (at) liberatedbread.com

We'll publish a PGP key here once our key infrastructure is set up. In the meantime, encrypted reports can be sent through GitHub's advisory system (below), or via our parent company's key — reach out through Discord for the fingerprint.

If you can't reach us at security@, try:

Machine-readable version: /.well-known/security.txt (RFC 9116).

Bug Bounty

We don't currently run a paid bug bounty program. We're a small project from a small company. That said, we'll happily:

Past Advisories

None yet. When we publish a security advisory, it will be linked here and in the GitHub Security Advisories page.


This policy was last updated July 2026. We'll update it as the project grows.