Skip to content

Security: theogony-project/theogony

Security

SECURITY.md

Security Policy

Scope

Security issues in Theogony are taken seriously, particularly those affecting:

  • the isolation of Lethe Vaults (private knowledge spaces must never leak into Akasha or other vaults)
  • access control and authentication in the API layer
  • PII exposure in extraction or retrieval outputs
  • the integrity of the Chronicle Ledger

Reporting a Vulnerability

Please do not report security vulnerabilities as public GitHub issues.

Instead, open a private GitHub Security Advisory: https://github.com/theogony-project/theogony/security/advisories/new

Include:

  • a description of the issue and its potential impact
  • steps to reproduce
  • any suggested remediation if known

We will acknowledge receipt within 72 hours and aim to resolve confirmed vulnerabilities within 30 days.

Disclosure Policy

We follow coordinated disclosure. We ask that you give us reasonable time to address the issue before public disclosure.

There aren't any published security advisories