Security issues in Theogony are taken seriously, particularly those affecting:
- the isolation of Lethe Vaults (private knowledge spaces must never leak into Akasha or other vaults)
- access control and authentication in the API layer
- PII exposure in extraction or retrieval outputs
- the integrity of the Chronicle Ledger
Please do not report security vulnerabilities as public GitHub issues.
Instead, open a private GitHub Security Advisory: https://github.com/theogony-project/theogony/security/advisories/new
Include:
- a description of the issue and its potential impact
- steps to reproduce
- any suggested remediation if known
We will acknowledge receipt within 72 hours and aim to resolve confirmed vulnerabilities within 30 days.
We follow coordinated disclosure. We ask that you give us reasonable time to address the issue before public disclosure.