The project is currently in pre-release (0.0.x). Only the main branch receives security fixes.
Please do not open a public GitHub issue for security vulnerabilities.
Instead, report privately via one of:
- GitHub Security Advisories: Open a private report
- Email: [to be added when published]
We will:
- Acknowledge receipt within 72 hours
- Investigate and confirm the issue
- Work on a fix in a private fork
- Publish a security advisory and release a patched version
- Credit you in the advisory unless you request anonymity
In scope:
- Vulnerabilities in the
chatbot_auditorPython package - Vulnerabilities in the optional FastAPI server
- Dependency vulnerabilities that affect this project
Out of scope:
- Vulnerabilities in external LLM providers (report to them)
- Vulnerabilities in chatbot platforms (Intercom, Zendesk — report to them)
- Social engineering of maintainers