Security & Trust
Kadmium develops high-performance developer tools and runtime systems engineered with a strict focus on privacy, system stability, and transparent code practices.
1. Responsible Vulnerability Disclosure
If you discover a potential vulnerability in any Kadmium utility, framework, or web endpoint:
Report Channel: Email full technical details directly to security@kadmium.dev.
Coordination: Provide reasonable time for remediation prior to disclosing details publicly.
Scope: Include proof-of-concept steps, affected binary builds, and environment conditions.
2. Executable Safety & SmartScreen Policy
Independent Software Distribution: Our desktop clients (such as Context Packer and Kadmium Launcher) are distributed as standalone, unpackaged executables without commercial EV code-signing certificates.
Zero Malicious Activity: Binaries contain zero third-party telemetry scrapers, bundled adware, or background crypto miners.
Inspectable Source: All shared engines and client solutions are available with inspectable C# and C++ source code under developer tiers to facilitate security audits.
3. Data Privacy & Local Execution
Offline-First Processing: Context Packer and runtime framework tools operate entirely on your local machine and make zero outbound network requests with your codebase.
Workstation Path Sanitization: Native routines identify and replace workstation account paths with [REDACTED] to prevent private username exposure in AI prompts.
Minimal Telemetry: Any optional crash diagnostic telemetry is fully anonymized and devoid of file contents, tokens, or network credentials.