Skip to content

Security: patonkikh/SafeGate

Security

SECURITY.md

Security Policy

Supported versions

Version Supported
2.0.x
1.0.x
< 1.0

Reporting a vulnerability

Please do not open public GitHub issues for security vulnerabilities.

Report privately via GitHub Security Advisories:

https://github.com/patonkikh/SafeGate/security/advisories/new

Include:

  • Description of the vulnerability
  • Steps to reproduce
  • Impact assessment
  • Suggested fix (if any)

We aim to acknowledge reports within 48 hours and provide a fix timeline within 7 days for confirmed critical issues.

Scope

In scope:

  • SafeGate Python SDK (src/safegate/)
  • AI Gateway and Dashboard servers
  • Policy engine and leak detection bypasses
  • Vault / audit log data exposure

Out of scope:

  • Third-party LLM provider APIs
  • Misconfiguration of deployment credentials (use .env, never commit secrets)

Safe disclosure

We follow coordinated disclosure. We will credit reporters in the changelog unless they prefer to remain anonymous.

There aren't any published security advisories