Security Vulnerability Disclosure
Effective date: 2026-07-27
SvrGuard is a security product, and the security of SvrGuard itself is our first priority. If you discover a vulnerability in SvrGuard, please report it privately — this protects every user until a fix ships.
1. How to report
- Security vulnerabilities (private): email ofuyuan@gmail.com with "SvrGuard Security" in the subject. Please include reproduction steps, affected version and environment.
- General questions and discussion (public): use the discussion forum — never post vulnerability details on the public forum.
Machine-readable format: /.well-known/security.txt
2. Our commitment
- We acknowledge reports within 3 business days.
- Once confirmed, we keep you informed of the fix plan and progress.
- For critical issues our goal is a fast over-the-air (OTA) fix — SvrGuard ships with signed self-update, so a patch can reach all subscribed users within days.
- We do not disclose vulnerability details before a fix is released, and we ask reporters to do the same (responsible disclosure).
- Reporters are credited by name in the fix announcement (unless you prefer to stay anonymous).
3. Scope
- SvrGuard agent and hub binaries (including the self-update mechanism)
- The official site svrguard.ofuyuan.com and the forum forum.ofuyuan.com