The Vexa Core maintainers take the security of the project seriously.
Please do not report security vulnerabilities through public GitHub issues, discussions, or pull requests.
Instead, report them privately by email to dmitry@vexa.ai. You may copy help@finos.org. Please include:
- a description of the vulnerability and its impact,
- steps to reproduce or a proof of concept,
- the affected versions / components, and
- any suggested mitigation.
We will acknowledge your report within 5 business days and keep you informed as we investigate and remediate. We follow a coordinated-disclosure process and will agree a public-disclosure timeline with you.
Vexa Core is under active development. Security fixes are applied to the main
branch and the latest release line. Please test against main before reporting.
The project tracks the OSPS Baseline (target: Maturity Level 2, a
FINOS Incubation commitment). Dated self-assessment results live in
security/osps-baseline/ — latest: 2026-07-02, 28 passed · 0 failed.