If you discover a security vulnerability in any AutomataNexus software, please report it responsibly.
DO NOT open a public GitHub issue for security vulnerabilities.
Email: devops@automatanexus.com
Subject: [SECURITY] <Product Name> — Brief description
Include:
- Product name and version
- Description of the vulnerability
- Steps to reproduce
- Potential impact assessment
- Suggested fix (if any)
| Stage | Timeline |
|---|---|
| Acknowledgment | Within 24 hours |
| Initial assessment | Within 72 hours |
| Fix development | Depends on severity |
| Patch release | Critical: 48 hours, High: 1 week, Medium: next release |
This policy covers all software distributed through the AutomataNexus Homebrew Tap:
- NexusFoundry
- AxonML
- NexusShield
- NexusSentinel
- Ferrum Email
We appreciate responsible disclosure. With your permission, we will credit you in the release notes for any confirmed vulnerability.
AutomataNexus LLC takes security seriously. Thank you for helping keep our software and users safe.