Volute ships a privileged daemon (root on system installs) that runs untrusted AI-authored code and exposes an HTTP API. Before inviting outside users, we want security researchers to have a private reporting channel — email in SECURITY.md and/or GitHub private vulnerability reporting — rather than public issues or social media.
Scope:
- Add
SECURITY.md: supported versions (latest release only, pre-1.0), how to report privately, expected response time.
- Enable GitHub private vulnerability reporting on the repo.
- Briefly state the threat model headline: minds are untrusted principals; the daemon API is the trust boundary (mirrors the security conventions in CLAUDE.md).
Part of the public-release readiness push.
Volute ships a privileged daemon (root on system installs) that runs untrusted AI-authored code and exposes an HTTP API. Before inviting outside users, we want security researchers to have a private reporting channel — email in SECURITY.md and/or GitHub private vulnerability reporting — rather than public issues or social media.
Scope:
SECURITY.md: supported versions (latest release only, pre-1.0), how to report privately, expected response time.Part of the public-release readiness push.