Skip to content

Security: HemantBK/chatbot-auditor

Security

SECURITY.md

Security Policy

Supported versions

The project is currently in pre-release (0.0.x). Only the main branch receives security fixes.

Reporting a vulnerability

Please do not open a public GitHub issue for security vulnerabilities.

Instead, report privately via one of:

We will:

  1. Acknowledge receipt within 72 hours
  2. Investigate and confirm the issue
  3. Work on a fix in a private fork
  4. Publish a security advisory and release a patched version
  5. Credit you in the advisory unless you request anonymity

Scope

In scope:

  • Vulnerabilities in the chatbot_auditor Python package
  • Vulnerabilities in the optional FastAPI server
  • Dependency vulnerabilities that affect this project

Out of scope:

  • Vulnerabilities in external LLM providers (report to them)
  • Vulnerabilities in chatbot platforms (Intercom, Zendesk — report to them)
  • Social engineering of maintainers

There aren't any published security advisories