Supported version
Security fixes are provided for the newest publicly available Fiscal Station HQ release. Users should install current releases promptly because older versions may no longer receive fixes.
Reporting a vulnerability
Report suspected vulnerabilities privately to [email protected] with the subject Security Report. Do not include real financial records, full backup files, account numbers, passwords, license keys, or other sensitive information in a public issue or initial report. The Publisher may request a minimal sanitized example after reviewing the report.
Include the Fiscal Station HQ version, operating system, reproduction steps, expected behavior, observed behavior, and the minimum sanitized sample needed to reproduce the issue.
The Publisher will acknowledge a report as reasonably practical, investigate it, and coordinate disclosure when appropriate. Do not publicly disclose an unresolved issue that could place users or their data at risk.
Local data responsibility
Fiscal Station HQ is an offline-first application and the Publisher does not serve as a remote backup or data custodian. Users should protect their operating-system accounts, enable device encryption, install security updates, and store Fiscal Station HQ backups safely.
The optional Cloud Sync Beta encrypts its working copy with AES-256-GCM before writing it to a user-selected synchronized folder. The key is derived from the user's passphrase and the remembered device key is protected with operating-system secure storage. The passphrase is not recoverable by the Publisher. Users should secure the associated cloud account, keep independent manual backups, and treat conflict-resolution choices as data-replacement operations.
