Reporting a security problem.
Write to info@deskstitch.com. You will get a reply, normally within a few working days, and you will be told what happens next.
What to send
Enough for the problem to be reproduced: what you did, what happened, and which versions of DeskStitch and Windows were involved. A proof of concept helps but is not required. Please do not include a pairing code or a license key; if one is central to the report, say so and it will be arranged separately.
What is in scope
The DeskStitch application, the installer and the update mechanism, and this website including the pages that handle purchases and licenses. Findings that depend on already having administrator rights on the PC, or on physical access to an unlocked machine, are worth reporting but are usually not treated as vulnerabilities.
What you can expect
An acknowledgement, an honest assessment of severity, and a fix or an explanation of why something is a deliberate trade-off. Fixes are described in the release notes. You will be credited if you want to be, and not if you prefer not. Nothing here is a bug bounty: DeskStitch is a one-person product and there is no money attached.
Please do not
Test against other people's machines, or against this site in ways that degrade it for other users. There is nothing to be gained from a denial-of-service demonstration, and it is the one thing that makes a report harder to act on.
Ordinary bugs and questions go to the support page, which is also just an e-mail.