Skip to content
Ichi

Ichi v0.1.0 Public Beta

Security

How to report a suspected vulnerability without exposing your documents or credentials.

Responsible disclosure

Please report suspected vulnerabilities privately to security@withichi.com. Give the developer a reasonable opportunity to investigate and address the issue before public disclosure. Ichi is an independent public beta, so there is no bug bounty.

Do not use the contact or bug-report forms for vulnerability disclosures. Use them only for general enquiries and reproducible defects with no security implications.

What to include

  • The affected Ichi version and your Windows environment.
  • A concise description of the impact and clear steps to reproduce it.
  • Whether the issue needs a specially crafted Markdown file or local access.
  • Proof-of-concept material that contains no real user data or live secret.

Protect private material

Do not send real documents, credentials, private keys, passwords or unredacted folder paths. Use a minimal synthetic Markdown file and replace identifying paths with neutral placeholders.

Getting Ichi safely

Ichi is available from Microsoft Store through the official Download page. Use Support for general usability problems or website content errors.