Skip to content

Security: Diyaaa-12/GaiaOS

Security

SECURITY.md

Security Policy

GaiaOS takes the security of our agentic risk intelligence platform and infrastructure seriously. We appreciate the contributions of security researchers and developers who help keep GaiaOS and its community safe.

Supported Versions

Only the latest release series receive active security updates and vulnerability patches.

Version Supported
4.x
< 4.0

Reporting a Vulnerability

Please do NOT report security vulnerabilities through public GitHub issues.

If you believe you have found a security vulnerability in GaiaOS, please disclose it responsibly by following these steps:

  1. Submit a Private Vulnerability Report: Submit a private security advisory through the GitHub repository's Security tab under "Report a vulnerability" (GitHub Private Vulnerability Reporting).
  2. Include Necessary Context:
    • Component / module affected (e.g., Auth, Gateway, Orchestrator, Evaluation Harness)
    • Step-by-step reproduction steps or Proof of Concept (PoC)
    • Impact assessment (e.g., privilege escalation, prompt injection bypass, data disclosure)
  3. Response SLA:
    • Initial acknowledgement: Within 48 hours
    • Severity triage & impact assessment: Within 5 business days
    • Remediation plan & target patch release date: Within 10 business days

Preferred Disclosure & Attribution

  • We practice coordinated vulnerability disclosure. We ask that you give us reasonable time to investigate and patch reported vulnerabilities before publicly disclosing them.
  • Reporters who follow responsible disclosure guidelines will be acknowledged in release notes and security advisories.

There aren't any published security advisories