Use GitHub's private security-advisory form for vulnerabilities that could expose participant data, bypass local-only processing, or alter the frozen production model and policy.
Do not include real meeting recordings, participant names, private reports, or credentials in an issue. Use a minimal synthetic example whenever possible.
Security fixes are currently provided for the latest ATTENTRIX public beta.
Every release publishes SHA-256 checksums beside the installer and portable archive. ATTENTRIX 0.2.0 Beta 2 is not code-signed, so verify its checksum before running it. A later signed build will be identified by a new release.