Tomo has not received a third-party security audit and is currently distributed as beta software. Only the latest release and the current main branch receive security fixes.
Please report suspected vulnerabilities privately by emailing dan@wvlen.llc. Include the affected version, reproduction steps, expected impact, and any suggested mitigation. Do not include API keys, credentials, private prompts, screenshots, or other sensitive user data in the report.
Please allow time to investigate before publishing details. This independently maintained project cannot promise a specific response or remediation timeline.