Skip to content

Security: beamup-run/beamup

SECURITY.md

Security policy

Current status

BeamUp implementation source has not been published in this repository. Do not use this repository as a software distribution or as evidence that a listed security control has been independently verified.

Reporting a concern

Do not open a public issue for:

  • suspected vulnerabilities
  • exploit details
  • credentials or tokens
  • private source or customer data
  • reusable endpoint or infrastructure identifiers

Use GitHub's private vulnerability reporting form or send a private report to team@beamup.run with [security] in the subject. Include only the minimum information required to understand the concern. Do not send live credentials or sensitive customer payloads.

We will coordinate disclosure after the report has been reviewed and the affected public or hosted surface is understood.

Claim boundary

Public specifications, tests, signed artifacts, and local verification each prove different things. None alone establishes production security, independent audit, compliance, or suitability for sensitive data.

There aren't any published security advisories