If you discover a potential security issue related to Swiftward (documentation, examples, or the core engine if you have access as a customer or partner), please report it responsibly.
Email: hello@swiftward.dev
We appreciate responsible disclosure and will work with you to assess and address valid reports.
In scope:
- Swiftward core engine (for customers and partners with access)
- Documentation or examples that could reasonably lead to insecure deployments
Out of scope:
- Social engineering
- Denial-of-service attacks against infrastructure not operated by Swiftward
- Vulnerabilities in third-party dependencies (please report to upstream projects)
Swiftward is designed for self-hosted, on-premises deployment. Customer data remains within the customer’s infrastructure.
The core engine does not require outbound network access and does not phone home for normal operation.
For additional context, see the FAQ.