Skip to content

Security: srex-dev/AgentResponsibilityEngineering

Security

SECURITY.md

Security Policy

Reporting A Vulnerability

Please do not open public GitHub issues for vulnerabilities, leaked credentials, private proof packets, protected evidence, raw payloads, or client-sensitive material.

Report privately to:

Jonathan Kershaw
jonathan.kershaw@gmail.com

Use a concise subject such as:

Security report: AgentResponsibilityEngineering

What Not To Include Publicly

Do not include any of the following in issues, pull requests, comments, screenshots, logs, or examples:

  • API keys, bearer tokens, credentials, or session cookies
  • raw HTTP headers
  • private keys, signatures, certificates, or seed material
  • protected evidence bodies
  • raw customer payloads
  • raw policy bodies that belong to a client
  • private ARE platform proof bundles
  • commercial Command Center or governance-strata internals

Scope

This repository is a public research and discipline mirror. It does not host the commercial ARE runtime or private proof systems.

Security issues in related private or commercial systems should be reported through the private channel above unless another repository provides a more specific security policy.

There aren't any published security advisories