Skip to content

Security: Vektor-Memory/Vex

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

Please email hello@vektormemory.com rather than opening a public GitHub issue.

I aim to respond within 7 days and will credit reporters by name or handle in release notes if they wish.

Supported Versions

Only the latest release receives security fixes.

Important: Protecting Yourself

We will never contact you asking for:

  • Your personal information
  • Your AES-256 credential vault files or vault passwords
  • Your API keys, tokens, or licence keys
  • Any files stored or generated by any VEKTOR tool

If you receive any message — email, GitHub issue, Discord, or otherwise — claiming to be from VEKTOR Memory and asking for any of the above, it is not from us. Do not respond. Report it to hello@vektormemory.com.

Data Storage Policy

VEKTOR Memory does not store any of your data on our servers — for any product, open source or closed source. Your memories, credentials, and vault files live on your machine only. We have no access to them and never will.

This applies to:

  • Vex (vector memory portability)
  • Vek-Sync (MCP config sync, AES-256 credential vault)
  • Via (CLI integration layer)
  • VEKTOR Slipstream SDK
  • Any future VEKTOR product

Your data belongs to you. That is not a policy. It is the architecture.

There aren't any published security advisories