Security

Reporting a Security Vulnerability

We take the security of HELIO seriously and welcome reports from security researchers and users who discover a potential vulnerability.

How to report

Please use our support form and select "Security Vulnerability / Incident" as the request type.
Your report should ideally include:
• Affected component (HELIO Client / Server) and version
• A short description of the issue
• Steps to reproduce or a proof of concept, if available

Support Form

What to expect

We aim to acknowledge every report within two business days and will keep you updated as we investigate and address the issue.

Responsible disclosure

We ask that you give us reasonable time to investigate and fix a reported issue before disclosing it publicly, and that you avoid accessing or modifying data that isn't yours during testing. We will not pursue legal action against good-faith security research conducted in line with this policy.