Folyo is a release-candidate implementation and must not yet be treated as a production-certified encrypted financial vault.
Use GitHub's private security advisory flow for this repository: https://github.com/Wyrcan-io/folyo/security/advisories/new. Do not put suspected vulnerabilities in public issues.
Do not include real financial statements, account numbers, credentials, vaults, backups, diagnostics, SMS content, or personal data in a report. Provide a synthetic or irreversibly redacted reproducer, affected version/commit, impact, and safe reproduction steps.
Critical or high integrity, privacy, recovery, signing, or exploitable security findings block alpha, beta, and stable release. See the threat model and incident response for the candidate process.