Skip to content
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
15 changes: 15 additions & 0 deletions SECURITY.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,15 @@
# Security policy

## Supported code

Only the latest `main` branch is considered for security fixes. This repository does not provide a supported public deployment or availability commitment.

## Reporting

Use GitHub private vulnerability reporting through the repository's **Security** tab when available. Otherwise email `contact@jadenrazo.dev` with the affected path, impact, and a minimal reproduction.

Do not open a public issue containing credentials, tenant or customer data, message or attachment contents, integration secrets, database records, or a working exploit against a reachable service.

## Scope

Authentication, tenant isolation, API and WebSocket authorization, chat and bot integrations, attachment handling, automation, AI-provider boundaries, database policies, and CI/release workflows are in scope. Dependency vulnerabilities should also be reported to the relevant upstream project.
Loading