Skip to content

Security: YuzeJ21/Scope-Proof

SECURITY.md

Security policy

Supported public alpha

The current public alpha is the supported version. ScopeProof is local-first, public-repository-only, and does not accept or require credentials beyond an optional GitHub token kept in the active local session.

Reporting a vulnerability

Do not post security vulnerabilities in public issues, pull requests, or discussions. Use GitHub's private vulnerability report for this repository and include a concise reproduction, affected version or commit, impact, and any safe mitigation you identified.

Do not include tokens, private repository links, customer data, or other confidential source material in a report.

Scope

Reports are most useful for local review storage, public GitHub ingestion, workflow isolation, deterministic evidence handling, exports, and dependency or supply-chain behavior. ScopeProof does not currently provide hosted, private-repository, billing, or paid-LLM features.

There aren't any published security advisories