Skip to content

Security: RoyMerlo/AVGVSTO

Security

SECURITY.md

Security Policy - AVGVSTO USB Encryption Suite

Supported Versions

We provide security updates for the following versions of AVGVSTO:

Version Supported
> 1.0.0
< 1.0.0

Reporting a Vulnerability

If you discover a security vulnerability within AVGVSTO (e.g., encryption bypass, hardware-binding failure, or issues with the self-destruct logic), please do not open a public Issue.

Instead, please submit a detailed report to: [merloroy200@gmail.com]

What to include in your report:

  1. A clear description of the vulnerability.
  2. Steps to reproduce the issue (Proof of Concept).
  3. Potential impact (e.g., "accessing encrypted data without the original USB token").

Our Commitment

We aim to respond to all reports within 48-72 hours. Once a fix is verified, we will coordinate a disclosure date and, with your permission, credit your contribution in our release notes.

Note: AVGVSTO is an Open Source project. We deeply value the work of independent security researchers in making this tool safer for everyone.

There aren’t any published security advisories