Skip to content

Security: ElxMaj/marrow

SECURITY.md

Security Policy

Marrow holds sensitive product-room evidence: transcripts, standups, interviews, decisions, and drift catches. Please report security issues through GitHub private vulnerability reporting for this repository.

Do not open a public issue for a vulnerability. Include:

  • affected package or surface
  • steps to reproduce
  • expected impact
  • any relevant logs or proof of concept

We prioritize issues that could expose raw evidence, connector secrets, model prompts, provenance spans, or database contents.

There aren't any published security advisories