Skip to content

Security: OneHillAI/AOI

Security

SECURITY.md

Security Policy

Reporting a vulnerability

If you discover a security issue in the AI Ownership Index tooling (the validation scripts, the site build, or the continuous integration workflows), please report it privately to dev@onehill.org rather than opening a public issue.

Include a description of the issue, the steps to reproduce it, and any relevant logs or configuration. We aim to acknowledge a report within a few working days and to agree a disclosure timeline with you.

Scope

This policy covers the code in this repository. It does not cover the third-party models or inference providers that the Index rates; concerns about those should go to the relevant publisher or provider.

Data

The repository stores only public primary-source clause extracts and their source URLs. It does not store secrets. If you believe a secret has been committed in error, report it to dev@onehill.org.

There aren't any published security advisories