Security and reporting

Documented boundaries. Responsible reporting.

The current alpha minimizes integration with target applications, but it has not completed a formal security review.

Current application security boundaries

No process injection

No DLL injection and no writes to another process's memory.

No driver

The current alpha does not install a kernel or display driver.

No saved screen content

Captured screen content is not saved by the documented implementation.

No transmitted screen content

Captured screen content is not uploaded or transmitted.

Current-user privilege model

SightAdapt runs with the current user's privileges. It reads limited window and process metadata needed to identify a selected application. An elevated target application may require SightAdapt to run at a compatible integrity level; do not weaken Windows protections as a workaround.

Emergency shutdown

The notification-area menu provides an emergency command that removes active overlays. Exiting SightAdapt also removes its overlay windows. Keep the command available during alpha testing.

Alpha security-review status

The current alpha has not completed a formal security review and must not be treated as production-ready assistive software. Protected content, remote sessions, graphics drivers and unusual privilege boundaries may behave differently.

See the current known limitations.

Report a vulnerability privately

Do not disclose security-sensitive issues in a public GitHub issue. Until a dedicated private reporting channel is configured, contact the repository owner through GitHub and request a private communication channel. Wait for that route to be agreed before sending technical detail.

Read the authoritative SECURITY.md.

Do not post publicly

  • Exploit code or step-by-step vulnerability details before coordination.
  • Private screenshots or captured application content.
  • Credentials, tokens, personal identifiers or confidential data.
  • Unredacted executable paths, usernames or organization names.