Skip to content

Security: Orthic-Labs/Membrane

Security

.github/SECURITY.md

Membrane security

Membrane is an internal, workspace-coupled control plane, not a standalone public service (README). Security claims below are limited to checked source, tests, or release contracts; missing proof is marked unavailable.

Report a vulnerability

Do not put secrets, exploit code, or private data in a public issue. The repository contains no published security mailbox or disclosure SLA (unavailable). Send a minimal private report to the maintainer/contact that came with your installation, including affected revision, platform, impact, reproduction, and a safe contact method. Request acknowledgement before sharing sensitive details. Do not test against another user's installation.

Security surface

Supported versions

Node.js >=20 is the declared runtime floor (package.json). The current MCP protocol and client support claims are generated in docs/clients/support-matrix.v1.json; unsupported or degraded cells must not be described as fully supported. There is no separately published security-support end date (unavailable).

Evidence rule

Documentation never upgrades a source-only claim into installed or published proof. Mac and Windows acceptance requires the receipts described in docs/release/macos.md and docs/release/windows.md.

There aren't any published security advisories