Skip to content

Security: AmirmLotfy/beavous

Security

SECURITY.md

Security policy

Report vulnerabilities privately to security@beavous.com. Do not open a public issue for a suspected tenant-isolation, credential, SSRF, or signed-URL vulnerability.

Beavous treats Backblaze B2 as the authoritative media store. Private media is never made public without an explicit verified publish operation. Supabase secret keys, B2 application keys, Gemini keys, database credentials, raw prompts, access tokens, cookies, and presigned URLs must never appear in client bundles, logs, manifests, screenshots, or Git history.

The public repository contains fictional product media only. Users are responsible for having rights to every source they upload or import.

There aren't any published security advisories