Skip to content

Security: Cerid-AI/cerid-ai

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

If you discover a security vulnerability in Cerid AI, please report it responsibly.

Email: security@cerid.ai

Please include:

  • A description of the vulnerability
  • Steps to reproduce
  • Potential impact
  • Any suggested fix (optional)

Response Timeline

  • Acknowledgment: within 48 hours
  • Initial assessment: within 5 business days
  • Fix or mitigation: as soon as practical, typically within 30 days

Scope

This policy applies to the code in this repository. Third-party dependencies are monitored via Dependabot and CI security scanning (bandit, pip-audit, Trivy, npm audit).

Supported Versions

Version Supported
Latest release Yes
Older releases Best effort

Disclosure

We follow coordinated disclosure. Please do not open public issues for security vulnerabilities.

There aren't any published security advisories