MUGSHOT Security Policy

Scope

MUGSHOT is currently a macOS preview candidate. Windows, iOS, Android, and store builds are not publicly supported. We accept reports of suspected authentication bypasses, unintended external transmission, artifact/signing tampering, permission misuse, and other vulnerabilities affecting a public candidate.

Report privately

Do not post an unpatched issue in a public issue, social post, or ntfy topic. Email yamamoto@mizukichilab.com with the subject MUGSHOT security report.

Include only what is necessary:

Do not send a real passcode, ntfy topic, evidence photo, signing key, personal data, or another person’s device data. If a sensitive attachment appears necessary, first send a summary and agree with us on an encrypted transfer method.

Response and coordinated disclosure

We aim to acknowledge a report within three business days, provide initial triage within seven business days, and update the reporter at least every fourteen days. These are targets, not guarantees. After validating impact, revoking credentials where needed, fixing and testing, and publishing a new version, we will coordinate disclosure with a reasonable update period for users. We will offer credit on request for lawful, good-faith research.

General support

Setup, compatibility, false alarms, and feature requests are not vulnerability reports. Use the Support page.