Security Policy

Last updated: September 13, 2025 (v0.3.2 Security Hardening Complete)

Our Commitment to Security

Security is a top priority for Mirenku. We take the protection of your data seriously and actively work to ensure Mirenku remains secure.

Reporting Security Vulnerabilities

🔒 Security Contact
Email: projects@aeturnis.dev
Subject Line: [SECURITY] Mirenku Vulnerability Report

Please DO NOT report security vulnerabilities through public GitHub issues, Discord, or other public channels.

What to Include in Your Report

Response Timeline

Severity Levels

Severity Description Resolution Target
Critical Remote code execution, authentication bypass, data breach 24-48 hours
High Privilege escalation, significant data exposure 1 week
Medium Limited data exposure, denial of service 2-4 weeks
Low Minor issues with limited impact Next release

Security Features in Mirenku

Authentication & Authorization

Data Protection

Network Security

Scope

This security policy applies to:

Out of Scope

The following are generally out of scope:

Recognition

We appreciate security researchers who help us keep Mirenku secure. With your permission, we'll acknowledge your contribution in our release notes and security hall of fame.

Legal Safe Harbor

We will not pursue legal action against security researchers who:

Known Security Considerations

Updates and Patches

Security updates are released as soon as possible after verification and fix development. We recommend all users stay on the latest version of Mirenku.

v0.3.2 Security Hardening (100% Complete)

The latest release includes comprehensive security enhancements:

Completed Security Enhancements

Security Testing

Security Architecture Deep Dive

For those interested in the technical details of Mirenku's security implementation:

Token Storage Architecture (Enhanced v0.3.2)

Mirenku uses a hardened multi-layer approach to protect MAL authentication tokens:

OAuth2 PKCE Implementation (Enhanced v0.3.2)

Our OAuth2 implementation exceeds RFC 7636 requirements with maximum security:

Protocol Handler Security

The custom mirenku:// protocol handler includes protections:

Database Security

Local SQLite database protections:

Network Communication

All external communications follow strict security guidelines:

Application Security

The desktop application includes these security measures:

Security Monitoring & Audit Logging (New in v0.3.2)

Comprehensive security event tracking with privacy protection:

Rate Limiting & Abuse Prevention (New in v0.3.2)

Protection against authentication abuse and token exhaustion:

Privacy by Design

Privacy is built into Mirenku's architecture:

Threat Model (Updated v0.3.2)

Mirenku is designed to protect against:

Mirenku does NOT protect against:

Questions?

For non-security questions: