Skip to content

Security: s2-streamstore/tailsurf

Security

SECURITY.md

Security policy

Reporting a vulnerability

Email security@s2.dev with the subject tail.surf security report.

Do not open a public GitHub issue for a suspected vulnerability.

Include the affected component, impact, reproduction steps, and any suggested remediation. Use test streams and synthetic content. Do not include another user's data or a live private link.

The reporting scope includes tail.surf, the tsf CLI, and the public Rust and TypeScript SDKs.

Avoid privacy violations, data destruction, service disruption, social engineering, denial of service, and access to data that is not yours. Give us a reasonable opportunity to investigate before public disclosure.

The current access model and reporting contacts are published at tail.surf/trust.

There aren't any published security advisories