The following versions of Splitter are currently supported with security updates:
| Version | Supported |
|---|---|
| 1.0.x | ✅ Yes |
| < 1.0 | ❌ No |
We take the security of Splitter seriously. If you believe you have found a security vulnerability, please report it to us responsibly.
Do not open a public GitHub issue for security vulnerabilities.
Please send security reports to: security@splitter.social (placeholder)
- A description of the vulnerability.
- Steps to reproduce the issue (proof of concept).
- Potential impact of the vulnerability.
- Any suggested mitigations.
- We will acknowledge receipt of your report within 48 hours.
- We will provide a timeline for fixes and keep you updated on progress.
- We will credit you for the discovery (unless you prefer to remain anonymous) once the fix is public.
Splitter employs several layers of security:
- Decentralized Identity (DID): Client-side key generation via Ed25519/ECDSA.
- End-to-End Encryption (E2EE): ECDH + AES-GCM for direct messaging.
- HTTP Signatures: All federated traffic is signed using instance-level and user-level keys.
- JWT Auth: Secure, short-lived session management.