Skip to content

Security: sujankim/jarvis-ai-platform

Security

SECURITY.md

Security Policy

Supported Versions

Version Supported
0.1.x ✅ Yes

Reporting a Vulnerability

Please do NOT report security vulnerabilities through public GitHub Issues.

Security issues reported publicly can be exploited before a fix is available.


How to Report

Open a private GitHub Security Advisory:

  1. Go to the Security tab of this repository
  2. Click "Report a vulnerability"
  3. Fill in the details

Or contact the maintainer directly via GitHub.


What to Include

  • Description of the vulnerability
  • Steps to reproduce
  • Potential impact
  • Your suggested fix (if any)

What to Expect

Step Timeline
Acknowledgement Within 72 hours
Assessment Within 7 days
Fix timeline communicated Within 14 days
Credit given In release notes

Scope

Security concerns include:

  • Authentication bypass
  • JWT vulnerabilities
  • SQL injection
  • Prompt injection at system level
  • API key exposure
  • Dependency vulnerabilities (CVEs)

Out of Scope

  • AI model hallucinations (not a security issue)
  • Slow response times
  • Feature requests

There aren't any published security advisories