If you discover a security vulnerability in any istariAI project, please report it responsibly. Do not open a public GitHub issue.
Instead, please email us at support@istari.ai with:
- A description of the vulnerability
- Steps to reproduce the issue
- Any relevant logs, screenshots, or proof-of-concept code
We will acknowledge receipt within 3 business days and aim to provide a resolution or mitigation plan within 14 business days.
Security updates are provided for the latest release of each actively maintained project. Archived repositories are no longer maintained and do not receive security updates.
We follow coordinated disclosure. We ask that you:
- Give us reasonable time to address the issue before public disclosure
- Avoid accessing or modifying other users' data
- Act in good faith to avoid disruption to our services