2026-09-01 16:51:19 +00:00
|
|
|
# Security
|
|
|
|
|
|
|
|
|
|
## Reporting vulnerabilities
|
|
|
|
|
|
|
|
|
|
Email **security@rakazo.com** only. Do not open public GitHub issues for security bugs.
|
|
|
|
|
|
|
|
|
|
Please include:
|
|
|
|
|
|
|
|
|
|
- Steps to reproduce
|
|
|
|
|
- Impact (what an attacker could do)
|
|
|
|
|
- Whether the issue is already public
|
|
|
|
|
|
|
|
|
|
We will acknowledge your report and work on a fix. Please do not file a public issue for unfixed vulnerabilities.
|
|
|
|
|
|
|
|
|
|
## Other contact
|
|
|
|
|
|
|
|
|
|
- General support: **support@rakazo.com**
|
|
|
|
|
- Maintainer: **elie@rakazo.com**
|
|
|
|
|
|
|
|
|
|
## Scope
|
|
|
|
|
|
2026-09-01 17:03:28 +00:00
|
|
|
This policy covers the BangSo Bot self-hosted product in **this repository**.
|
2026-09-01 16:51:19 +00:00
|
|
|
|
|
|
|
|
Out of scope:
|
|
|
|
|
|
|
|
|
|
- Third-party AI models and their APIs
|
|
|
|
|
- Composio, E2B, and other external services
|
|
|
|
|
- Operator misconfiguration (exposed secrets, open databases, weak passwords)
|
|
|
|
|
|
|
|
|
|
## Supported versions
|
|
|
|
|
|
|
|
|
|
We support security fixes on the current `main` branch and the latest release (beta).
|
|
|
|
|
|
|
|
|
|
There is no bug bounty program at this time.
|