Security: thecharge/companion
Security
API endpoints require secret authentication.
Server responses now include baseline security headers.
Tool execution supports container sandboxing.
Replace static shared secret with OIDC/JWT authn.
Add role-based authorization for sessions/tools/admin APIs.
Enforce TLS termination with mTLS in internal deployments.
Add per-tool policy controls:
filesystem scope
network egress policy
process runtime limits
Do not store production secrets in .env files committed to git.
Use vault/KMS and rotate periodically.
Use separate credentials per environment.
Generate SBOM for each release.
Sign container and binary artifacts.
Block known vulnerable dependencies in CI.
Incident Response Minimum
Severity matrix and paging policy
Forensic log retention period
Recovery runbooks with ownership
Post-incident review and corrective actions
There aren't any published security advisories
You can’t perform that action at this time.