Skip to content

Security: AcadifySolution/ai-evals-framework

Security

SECURITY.md

Security\n\nThis evaluation framework processes potentially sensitive prompts, model outputs, contexts, and credentials.\n\n## Controls\n\n- Never commit API keys, database passwords, or cloud credentials.\n- Treat evaluation datasets and generated outputs as potentially sensitive.\n- Avoid logging full prompts/outputs in production logs unless explicitly required.\n- Use bounded concurrency and validate configuration values before remote calls.\n- Review third-party model/provider endpoints before use.\n- Validate Terraform and use secret managers rather than hard-coded credentials.\n- Treat local fallback metrics as heuristics, not equivalent substitutes for a calibrated evaluator.\n\nReport security issues privately to the maintainers.

There aren't any published security advisories