Skip to content

Security: OpenSIN-AI/OpenSIN-Code

Security

SECURITY.md

Security Policy

Supported Versions

Version Supported
0.1.x

Reporting a Vulnerability

We take security seriously. If you discover a vulnerability in OpenSIN Code, please follow these steps:

  1. DO NOT open a public issue
  2. Use GitHub Security Advisories or email security@opensin.ai
  3. Include: description of the vulnerability, steps to reproduce, potential impact, suggested fix

Response Timeline

  • Initial response: Within 48 hours
  • Assessment: Within 5 business days
  • Fix deployment: Critical: 7 days, High: 14 days, Medium: 30 days

Security Best Practices

  • Never commit API keys, tokens, or secrets to the repository
  • Use environment variables for sensitive configuration
  • Review all dependencies for known vulnerabilities
  • Keep all packages up to date
  • Use the built-in permission system to restrict tool access

Responsible Disclosure

We follow a responsible disclosure policy. Security researchers who report valid vulnerabilities will be credited in our security acknowledgments.

There aren’t any published security advisories