During the release-candidate period, the current main branch and the latest
v1.0.0-rc.x GitHub prerelease receive security updates. Superseded release
candidates are not supported.
Use the repository's private GitHub Security Advisory form. Do not disclose a suspected vulnerability in a regular issue, discussion, screenshot, or public channel.
Include a concise impact description, reproduction steps, and affected commit. Remove all API credentials, encryption keys, personal data, and paid provider response bodies from the report.
- Keep DataForSEO credentials in
.envor the encrypted Connections store. - Keep the encryption key in
.envor a private file referenced byKEYWORD_PRO_ENCRYPTION_KEY_FILE. - Use a unique 32-byte base64
KEYWORD_PRO_ENCRYPTION_KEYfor each environment. - For rotation, use named 32-byte keys in
KEYWORD_PRO_ENCRYPTION_KEYSand setKEYWORD_PRO_ENCRYPTION_KEY_ACTIVEto the current write key. - Legacy encryption aliases are read only for private-preview compatibility. Startup stops if canonical and legacy values disagree.
- Never reuse the CI placeholder key outside CI.
- Treat saved reports and exported provider responses as private data.
- Keep legacy compatibility exports outside the repository. They contain cached provider responses and retained encrypted credential values even though the export command never decrypts them.
- Rotate credentials immediately if they appear in logs or screenshots.
- The documented startup command rejects malformed database TLS settings and encryption-key material before opening the application port.
Keyword Pro is designed for one user on one machine and binds to 127.0.0.1 by
default. Direct LAN or internet exposure is unsupported without authentication,
trusted secret management, shared rate limiting, privacy-safe observability,
and a deployment-specific threat review.
Set DATABASE_SSL_MODE=disable only for the bundled loopback PostgreSQL
service. Use DATABASE_SSL_MODE=require for a hosted database that supports
TLS.