Skip to content

Security: guriguri215-lang/decision-assurance-framework

SECURITY.md

Security policy

Supported release

Security fixes are evaluated for the current source release. This project does not promise a response or remediation service-level agreement, long-term support window, or backward-compatible public Python API.

Report a vulnerability

Use GitHub private vulnerability reporting for this repository. Do not open a public Issue for a suspected vulnerability and do not include credentials, P2/P3 data, real decision records, raw prompts or responses, private paths, or Private Vault material in any report.

If private vulnerability reporting is unavailable, do not substitute a public Issue or pull request. Wait for the repository owner to publish a verified private route.

Scope and boundaries

Useful reports identify a reproducible security defect in the source code, privacy gates, publication controls, record validation, Tool isolation, audit binding, or human decision boundary using synthetic P0/P1 data. The framework is advice-only and has no external-effect executor.

The publication scanner, sandbox configuration, and deterministic hashes are defense-in-depth controls rather than proof of host isolation, provider authenticity, physical erasure, or freedom from every vulnerability. See the threat model and known limitations.

There aren't any published security advisories