Please report suspected FrostByte vulnerabilities through GitHub's private vulnerability reporting form. It is separate from public issues. GitHub's private reporting guide explains how a report is handled.
If you cannot use that route, contact support@blackfrostai.com with the subject FrostByte security report and a brief description. Ask for a suitable private follow-up channel before sending sensitive attachments. Do not include credentials or active invite codes.
- The FrostByte version, affected platform, and relevant feature.
- The expected security boundary and what appeared to go wrong.
- The impact you observed, with sensitive information removed.
- Any conditions needed to understand the issue, using only systems and test data you are authorized to use.
The current release listed on the official download page is the primary maintenance target. Reports affecting older builds are welcome; include the exact version. Do not retry a potentially harmful action against another person's device, data, or production service to complete a report.
Please coordinate sensitive details privately while maintainers investigate. Public disclosure timing is discussed case by case. This policy does not establish a paid bug bounty, a response-time guarantee, or authorization to test third-party systems.
Ordinary crashes, UI problems, and feature requests without a security impact belong in the public issue chooser. Personal support details belong in private support.