Hermex aims for a safe and auditable API.
If you discover a security issue, do not share details in public issues. Please contact the maintainer privately using the repository's preferred security channel. Include reproduction steps, impact, and a short proof-of-concept patch if possible.
Current scope is non-financial and includes:
- Birth/location/time input validation
- Query sanitization and size limits
- Endpoint resilience for malformed payloads
- Confirm, fix, and verify internally before public disclosure.
- Add changelog notes for high-impact fixes.
- Never commit API keys or secrets.