Please use GitHub's private reporting: Security → Report a vulnerability (https://github.com/nixfred/blip/security/advisories/new). Do not open a public issue for anything exploitable.
Blip's threat model, trusted computing base (the Mac), and the findings of the 2026-08-31 audit are in docs/SECURITY.md. What touches disk on each machine is in docs/PRIVACY.md.
Supported: the latest tagged release only.