Security Policy

Serin is a self-hosted, single-user portfolio tracker. This document explains what Serin protects, what it deliberately does not, and how to report issues.

Reporting a vulnerability

Open a GitHub security advisory (Security → Report a vulnerability) or email the maintainer privately. Please do not file public issues for exploitable bugs. You can expect an acknowledgement within a week; fixes ship as patch releases with credit unless you prefer otherwise.

Threat model

In scope — what Serin defends against:

Out of scope — deploy-time responsibilities:

Data flows (privacy)

Data Where it goes When
Positions, transactions Local SQLite only always
Symbols (not quantities) Market-data provider price refresh / history
Portfolio snapshot + headlines Your configured AI provider only when a briefing or Smart Import runs
Uploaded statements/screenshots Your configured AI provider only via Smart Import, after an explicit user action

Supported versions

The latest minor release receives security fixes. Older versions: please upgrade — migrations run automatically on startup.