Augur OS is under active development. Security fixes are applied to the latest state of the main branch.
Augur is local-first, not offline-only. Its SQLite database and generated profiles are stored locally, but company prompts and research context are sent through the locally installed Claude CLI. When Apollo is enabled, requested enrichment data is sent to Apollo. Review those providers' retention and privacy terms before processing confidential or regulated data.
Apollo credentials are stored in the application data directory. On Unix Augur restricts the key file to the current user; other platforms do not yet have equivalent OS-keychain storage. Do not use a high-privilege or shared Apollo key.
| Version | Supported |
|---|---|
Latest main |
Yes |
| Older releases | No |
Please do not open a public issue for security vulnerabilities.
Report vulnerabilities privately through GitHub:
- Open the Security tab of this repository.
- Click Report a vulnerability to start a private security advisory.
Please include:
- A description of the vulnerability and its potential impact.
- Steps to reproduce it.
- The affected version or commit hash.
We aim to acknowledge reports within a few business days and will keep you updated as we work on a fix. Once a fix ships, we are glad to credit you in the advisory unless you prefer to stay anonymous.
Thank you for helping keep Augur OS and its users safe.