Skip to content

Security: RayyanAlam1/esg-nexus

Security

SECURITY.md

Security Policy

Supported versions

Version Supported
main / latest release yes
older tags no

Reporting a vulnerability

Please do not open a public issue. Report vulnerabilities privately through GitHub Security Advisories. You will receive an acknowledgement within 5 working days and a resolution plan within 30 days for confirmed issues.

Scope

  • Authentication, authorization (RBAC, tenant isolation, entity scoping)
  • AI guardrails (prompt injection, data leakage, unsupported claims)
  • Ingestion and document handling
  • Report generation and file storage

The platform's security architecture is described in docs/SECURITY.md.

There aren't any published security advisories