Skip to content

docs: add SECURITY.md with a vulnerability disclosure policy #827

Description

@psamiton

Volute ships a privileged daemon (root on system installs) that runs untrusted AI-authored code and exposes an HTTP API. Before inviting outside users, we want security researchers to have a private reporting channel — email in SECURITY.md and/or GitHub private vulnerability reporting — rather than public issues or social media.

Scope:

  • Add SECURITY.md: supported versions (latest release only, pre-1.0), how to report privately, expected response time.
  • Enable GitHub private vulnerability reporting on the repo.
  • Briefly state the threat model headline: minds are untrusted principals; the daemon API is the trust boundary (mirrors the security conventions in CLAUDE.md).

Part of the public-release readiness push.

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions