LocalEndpoint ConnectPrivate AI for Windows
Menu

Responsible reporting

Report a security issue

Report a suspected LocalEndpoint security issue safely, with a bounded scope, redacted evidence, and honest current response expectations.

Responsible reporting

Help us investigate without exposing anyone else

Use this policy for a suspected vulnerability in LocalEndpoints.com or the current LocalEndpoint Connect early-access build.

Include

  • Affected URL, component, version, and release hash.
  • The security impact in plain language.
  • Minimal, repeatable steps using test data you own.
  • Redacted timestamps, request IDs, or screenshots needed to understand the issue.

Do not include or attempt

  • Passwords, session cookies, access tokens, workspace keys, private prompts, or unrelated personal files.
  • Access to another person’s account, device, endpoint, memory, or model data.
  • Destructive testing, persistence, denial of service, social engineering, or automated broad scanning.
  • Public disclosure of an unpatched issue before a private coordination path exists.

Current response expectations

No verified public security inbox, response-time commitment, bug bounty, or legal safe-harbor policy is published yet. Invited testers should use the original private invitation channel, label the message “Security report,” and share only the minimum redacted evidence.

Operating boundary

Public clarity, local authority.

Public product, docs, download, and validation pages do not dispatch desktop commands, probe localhost, upload files, collect runtime telemetry, or claim runtime safety certification. Account credentials are accepted only on dedicated account routes.

Website explainsNo public command dispatch Browser checksNo upload intake Your work stays localNo localhost probing Verify downloadsChecksum-backed artifacts