Skip to content

Security: evtran0209/Hotbound-AI

SECURITY.md

Security Policy

Supported Versions

Version Supported
1.0.x

Reporting a Vulnerability

If you discover a security vulnerability within Hotbound-AI, please follow these steps:

  1. DO NOT disclose the vulnerability publicly
  2. Send a detailed report to evtran0209@gmail.com
  3. Include:
    • Description of the vulnerability
    • Steps to reproduce
    • Potential impact
    • Suggested fix (if possible)

You can expect:

  • Initial response within 48 hours
  • Regular updates on the progress
  • Full credit for the discovery (if you wish)

Security Measures

  • All API keys and sensitive credentials are stored in environment variables
  • Dependencies are regularly updated via Dependabot
  • Code scanning is enabled to detect potential security issues
  • Secret scanning is enabled to prevent accidental commits of tokens

There aren't any published security advisories