If you discover a security vulnerability, please report it responsibly.
Email: security@anyfoundry.dev
Do not use public GitHub issues for security reports.
- Acknowledgment: within 48 hours
- Initial assessment: within 5 business days
- Critical fixes: within 14 days
- The ScribeFoundry application
- Build and release pipeline
- Direct dependencies
- Third-party services or dependencies with their own security processes
- Social engineering
We follow coordinated disclosure. We will credit reporters in release notes unless they prefer to remain anonymous.