BangSo/SECURITY.md

35 lines
877 B
Markdown

# Security
## Reporting vulnerabilities
Email **security@rakazo.com** only. Do not open public GitHub issues for security bugs.
Please include:
- Steps to reproduce
- Impact (what an attacker could do)
- Whether the issue is already public
We will acknowledge your report and work on a fix. Please do not file a public issue for unfixed vulnerabilities.
## Other contact
- General support: **support@rakazo.com**
- Maintainer: **elie@rakazo.com**
## Scope
This policy covers the BangSo Bot self-hosted product in **this repository**.
Out of scope:
- Third-party AI models and their APIs
- Composio, E2B, and other external services
- Operator misconfiguration (exposed secrets, open databases, weak passwords)
## Supported versions
We support security fixes on the current `main` branch and the latest release (beta).
There is no bug bounty program at this time.