| Version | Supported |
|---|---|
| 2.0.x | ✅ |
| 1.0.x | ✅ |
| < 1.0 | ❌ |
Please do not open public GitHub issues for security vulnerabilities.
Report privately via GitHub Security Advisories:
https://github.com/patonkikh/SafeGate/security/advisories/new
Include:
- Description of the vulnerability
- Steps to reproduce
- Impact assessment
- Suggested fix (if any)
We aim to acknowledge reports within 48 hours and provide a fix timeline within 7 days for confirmed critical issues.
In scope:
- SafeGate Python SDK (
src/safegate/) - AI Gateway and Dashboard servers
- Policy engine and leak detection bypasses
- Vault / audit log data exposure
Out of scope:
- Third-party LLM provider APIs
- Misconfiguration of deployment credentials (use
.env, never commit secrets)
We follow coordinated disclosure. We will credit reporters in the changelog unless they prefer to remain anonymous.