Skip to content

Security: saagar210/AssistSupport

SECURITY.md

Security Policy

Reporting a Vulnerability

If you discover a security vulnerability in AssistSupport, please report it responsibly.

Do not open a public GitHub issue for security vulnerabilities.

How to Report

  1. GitHub Security Advisories (preferred): Use GitHub's private vulnerability reporting to submit details.
  2. Email: Contact the maintainers directly (see profile).

What to Include

  • Description of the vulnerability
  • Steps to reproduce
  • Potential impact
  • Suggested fix (if any)

Response Timeline

  • Acknowledgment: Within 48 hours
  • Initial assessment: Within 1 week
  • Fix or mitigation: Depends on severity

Scope

This policy covers the AssistSupport application code. Third-party dependencies should be reported to their respective maintainers.

Security Model

For the full security architecture, encryption details, and threat model, see docs/SECURITY.md.

There aren’t any published security advisories