Skip to content
Applio
Security

Security policy

The security of our users and the trust of our community are taken seriously. This page explains how to report a vulnerability and what you can expect from us in return.

Reporting a vulnerability

If you believe you have found a security vulnerability in Applio, its website, or its documentation, please report it privately through GitHub's private vulnerability reporting. Do not open a public issue or share details in public channels before the issue has been addressed.

What to include in your report

The more context you provide, the faster we can assess the issue. Helpful details include:

  • The Applio version and operating system you are using.
  • A description of the vulnerability and the steps to reproduce it.
  • The potential impact (e.g. data exposure, privilege escalation).
  • Any suggested fix or mitigation, if you have one.

What happens next

  • Your report is acknowledged by a maintainer, usually within a few days.
  • We investigate the issue and work on a fix, keeping you informed of the progress.
  • Once fixed, a patch is released and the vulnerability is disclosed responsibly, giving credit to the reporter when appropriate.

Our security posture

Local-first by design

Applio runs entirely on your machine. Your audio and models never leave your device unless you choose to share them — there is no account, no telemetry, and no cloud dependency for core features.

Open and auditable

All source code is public and MIT-licensed, so anyone can review it. Dependencies are pinned and updated through automated workflows.

Use trusted models

Your data stays on your machine, but models come from external sources. Only use models from sources you trust, verify the integrity of files you download, and be careful with models shared in public communities.

Keep Applio updated

The easiest way to stay secure is to run the latest release. Fixes and improvements are released through our regular update channels.

As with all open source software, Applio is provided "as is" without warranty. For details on your rights and responsibilities, see the Terms of Use, the MIT License, or reach out on Discord.