MIG Core is an execution control engine for critical infrastructure. We take security seriously.
If you discover a security vulnerability in MIG Core, please report it responsibly.
Do NOT open a public GitHub issue for security vulnerabilities.
Instead, email: neel@houseofgalatine.com
Include:
- Description of the vulnerability
- Steps to reproduce
- Potential impact
- Suggested fix (if any)
You will receive a response within 48 hours.
This policy covers the MIG Core codebase in this repository. It does not cover:
- The MIG Playground (client-side demo at houseofgalatine.com/playground)
- The production MIG engine (proprietary, not in this repo)
- Third-party dependencies
We ask that you:
- Give us reasonable time to fix the issue before public disclosure
- Do not exploit the vulnerability beyond what is necessary to demonstrate it
- Do not access or modify other users' data
Security researchers who report valid vulnerabilities will be credited in our changelog (with permission).
Security: neel@houseofgalatine.com Website: houseofgalatine.com