This policy applies to every repository of the zensation-ai organization that has no SECURITY.md of its own.
Repositories with their own policy (for example zenbrain)
also list their supported versions there.
Please do not open public GitHub issues for security vulnerabilities.
Report them to security@zensation.ai, or use GitHub's private vulnerability reporting where a repository has it enabled.
Please include:
- a description of the vulnerability
- steps to reproduce
- the potential impact
- a suggested fix, if you have one
| Action | Timeframe |
|---|---|
| Acknowledgment | within 48 hours |
| Initial assessment | within 5 business days |
| Fix timeline provided | within 10 business days |
| Patch release | as soon as the fix is verified |
We ask that you:
- give us reasonable time to fix the issue before public disclosure
- make a good-faith effort to avoid privacy violations and data destruction
- not exploit the vulnerability beyond what is necessary to demonstrate it
We will:
- acknowledge your report promptly
- keep you informed of our progress
- credit you in the security advisory, unless you prefer otherwise