Skip to content

Security: 3nesdeniz/ai-security-roadmap

SECURITY.md

Security Policy

Scope

This repository contains educational documents, validation scripts, and synthetic lab fixtures. Security reports may concern the scripts, workflows, dependency choices, unsafe lab instructions, exposed sensitive data, or a source link that has been taken over and now serves harmful content.

Reporting

Do not publish a working exploit or sensitive material in a public issue. Use GitHub's private vulnerability-reporting feature when it is enabled for the repository. If private reporting is unavailable, contact the maintainer through the security contact listed on the GitHub profile and include only enough information to establish the issue.

Include:

  • the affected file and revision;
  • the risk and realistic impact;
  • minimal reproduction steps using synthetic data;
  • a proposed remediation if available.

Supported version

Only the current default branch is maintained. Historical revisions are educational snapshots and do not receive security updates.

Safe research

The project does not authorize testing any third-party system. A repository example is not permission to send it to a live endpoint. Use local or synthetic targets and follow the scope, data-handling, stop, and disclosure rules in the guide.

There aren't any published security advisories