Tidy is architected as a Local-First, Sovereign Intelligence Platform:
- All cognitive memories, SQLite nodes, micro-app data (tasks, snippets, reflections), and vault credentials remain exclusively on your local machine (
~/.tidy/tidy.db). - Tidy contains zero background telemetry, zero third-party analytics trackers, and zero cloud lock-in sync daemons.
- The desktop application runs with strict Electron context isolation (
contextIsolation: true,nodeIntegration: false).
Security patches and bug fixes are actively provided for the following releases:
| Version | Supported |
|---|---|
1.4.x |
β Yes (Current Active Release) |
< 1.4.0 |
β No (Please upgrade to v1.4.0+) |
If you discover a security vulnerability in Tidy, please do not open a public GitHub issue.
Instead, please report it through one of the following private channels:
- GitHub Private Vulnerability Reporting: Use the "Report a vulnerability" button under the Security tab of this repository.
- Security Email: Send an encrypted or plain email to
security@tidyfactor.com.
- A clear description of the vulnerability and its potential impact.
- Step-by-step reproduction instructions or proof-of-concept (PoC).
- Affected version and operating system environment.
- We will acknowledge receipt of your report within 24 hours.
- We will provide an assessment and timeline within 72 hours.
- Once a fix is verified, a patched release will be published alongside a coordinated security advisory.