Skip to content

Security: loehrning-ai/platform

SECURITY.md

Security Policy

Reporting a vulnerability

Do not open a public issue, pull request, or discussion for a suspected vulnerability.

Send a private report to tim@loehrning.ai. Include the affected route or component, impact, reproduction steps, and a minimal proof of concept. Remove credentials, personal data, and production records before sending evidence.

If GitHub private vulnerability reporting is enabled, the repository Security tab is an equivalent private channel.

Scope

Supported code is the current default branch after publication. Dependency alerts, secret exposure, authentication bypass, cross-site scripting, server-side request forgery, data leakage, and unsafe content execution are in scope. General product questions and factual content corrections belong in the support process.

Acknowledgement is targeted within five business days. Fix and disclosure timing depends on severity and reproducibility.

There aren't any published security advisories