Stalkrr
Security

Security

Reporting a vulnerability, and the audit history.

Stalkrr captures meetings and voice calls. A security or privacy bug here can expose extremely sensitive data, so we treat the following as security issues, not ordinary bugs:

Reporting a vulnerability

Please do not open a public issue or PR for security/privacy vulnerabilities.

Report privately:

The verifiable inventory of every network connection the app can make lives in PRIVACY.md; anything off-device that isn't listed there qualifies as a vulnerability.

Please include: affected version/commit, a description, reproduction steps, and the data-boundary impact. We aim to acknowledge within a few business days. Please give us reasonable time to remediate before public disclosure (coordinated disclosure).

Supported versions

Alpha, under active daily development. Only the latest release on stalkrr-releases is supported — installed builds self-update, so staying current is automatic. Treat the software's judgment-free capture with the care it deserves: you are responsible for recording lawfully (see docs/CONSENT.md).

Audit history