The Aether engineering team takes the security of our autonomous financial intelligence platform seriously. We appreciate responsible disclosure of security vulnerabilities.
We release security updates for the following supported versions:
| Version | Supported |
|---|---|
0.1.x (Main / Head) |
✅ Supported |
< 0.1.0 |
❌ End of Life |
If you discover a security vulnerability or potential security risk in Aether, please follow our responsible disclosure procedure:
- Do NOT open a public GitHub issue.
- Report the vulnerability privately via GitHub Private Security Advisory or contact the maintainer directly via GitHub Profile.
- Include the following details in your advisory report:
- Description of the vulnerability and potential impact.
- Proof of Concept (PoC) or step-by-step instructions to reproduce.
- Component affected (
api,mcp-server,qdrant,neo4j, etc.).
- Initial Acknowledgment: Within 48 hours of receiving your report.
- Triage & Status Update: Within 5 business days, detailing vulnerability assessment and fix timeline.
- Public Release & Advisory: Security patch released within 14 business days along with credit attribution (if requested).
Thank you for helping keep Aether secure for everyone!