Skip to content
Dummy BI

Security

Local-first processingNo report data uploadedRelease integrity checks

Reporting a Vulnerability

Please do not report security vulnerabilities through public GitHub issues.

Send a private report

support@dummy-bi.com

Include a description of the issue, steps to reproduce, and the version you were using. We review all reports and respond as soon as we can. Responsible disclosure is credited unless you prefer anonymity.

Your Report Data Never Leaves Your Machine

The core documentation and datasource-switching features read your Power BI files locally and write output back to the same folder. No report data passes through Dummy BI servers.

The optional API connectors — Power BI service, Fabric, Azure DevOps, GitHub, and Databricks — connect directly to those services using credentials you provide. They are only activated when you explicitly use them. Dummy BI never sees or stores those credentials or the data returned.

Website signups, feedback, purchases, license delivery, and support emails are handled separately under the Privacy Policy.

Background network activity is limited to update checks and, where enabled, license validation. Sign-in and optional service connectors use the network only when you configure or invoke them. None of these requests route report contents through Dummy BI servers.

Supply Chain Security

Automated CI checks dependencies across all three ecosystems used by the tool. Release builds stop on unacknowledged high-severity dependency findings. The additional supply-chain scanner runs when its repository credential is configured.

EcosystemToolWhat it catches
Pythonpip-auditKnown CVEs in PyPI packages
PythonHash-verified installsTampered or replaced packages
Node.jsnpm auditHigh/critical vulnerabilities
Rustcargo auditSecurity advisories in crates
AllSocket.dev (configured CI)Malicious packages, typosquatting

Verifiable Releases

The public release workflow is configured to produce:

SBOM

CycloneDX format

A complete list of every bundled dependency.

SHA-256 checksums

All installers

Verify file integrity before running.

Authenticode

Windows binaries

Publisher signatures on the installer and bundled executables.

Public installers, checksums, and SBOM files will be published on our GitHub Releases page.

Contact

support@dummy-bi.com