Skip to content

Security: zensation-ai/.github

Security

SECURITY.md

Security Policy

This policy applies to every repository of the zensation-ai organization that has no SECURITY.md of its own. Repositories with their own policy (for example zenbrain) also list their supported versions there.

Reporting a vulnerability

Please do not open public GitHub issues for security vulnerabilities.

Report them to security@zensation.ai, or use GitHub's private vulnerability reporting where a repository has it enabled.

Please include:

  • a description of the vulnerability
  • steps to reproduce
  • the potential impact
  • a suggested fix, if you have one

Response timeline

Action Timeframe
Acknowledgment within 48 hours
Initial assessment within 5 business days
Fix timeline provided within 10 business days
Patch release as soon as the fix is verified

Responsible disclosure

We ask that you:

  1. give us reasonable time to fix the issue before public disclosure
  2. make a good-faith effort to avoid privacy violations and data destruction
  3. not exploit the vulnerability beyond what is necessary to demonstrate it

We will:

  1. acknowledge your report promptly
  2. keep you informed of our progress
  3. credit you in the security advisory, unless you prefer otherwise

There aren't any published security advisories