Skip to content

Security: ferro-labs/ferrolabs-typescript-sdk

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

Do not open a public GitHub issue for security vulnerabilities.

Please report security issues by emailing: hello@ferrolabs.ai

You can expect an acknowledgement within 48 hours and a full response within 7 days.

Scope

This policy covers the ferrolabsai npm package. For gateway-level security issues, report to the ai-gateway repository.

Secure Usage

  • Never hardcode API keys. Use environment variables (FERRO_API_KEY).
  • Always use HTTPS for non-localhost baseUrl.
  • Rotate API keys regularly.

There aren't any published security advisories