Skip to content

Security: tsnAnh/ScribeFoundry

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

If you discover a security vulnerability, please report it responsibly.

Email: security@anyfoundry.dev

Do not use public GitHub issues for security reports.

Response Timeline

  • Acknowledgment: within 48 hours
  • Initial assessment: within 5 business days
  • Critical fixes: within 14 days

Scope

  • The ScribeFoundry application
  • Build and release pipeline
  • Direct dependencies

Out of Scope

  • Third-party services or dependencies with their own security processes
  • Social engineering

Disclosure

We follow coordinated disclosure. We will credit reporters in release notes unless they prefer to remain anonymous.

There aren't any published security advisories