Skip to content

Security: Delavalom/graft

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

If you discover a security vulnerability in Graft, please report it responsibly.

Do not open a public GitHub issue for security vulnerabilities.

Instead, please email: security@delavalom.com

You should receive a response within 48 hours. We will work with you to understand the issue and coordinate a fix before any public disclosure.

Supported Versions

Version Supported
Latest Yes

Scope

This policy covers the Graft library itself. Issues in upstream providers (OpenAI, Anthropic, Google, AWS) should be reported to those providers directly.

There aren't any published security advisories