Skip to content

Security: Olawoyin007/empathySync

Security

.github/SECURITY.md

Security Policy

Supported Versions

Version Supported
Latest

Reporting a Vulnerability

empathySync takes security seriously, especially given our focus on user wellbeing and safety-critical features.

Critical Issues (Report Immediately)

If you discover a vulnerability in:

  • Crisis detection (bypasses that could miss suicidal ideation)
  • Harmful content blocking (ways to extract dangerous information)
  • Data privacy (unintended data transmission or exposure)

Please report these privately by opening a private security advisory on GitHub.

Do NOT open a public issue for security vulnerabilities.

What to Include

  • Description of the vulnerability
  • Steps to reproduce
  • Potential impact
  • Suggested fix (if you have one)

Response Timeline

  • Acknowledgment: Within 48 hours
  • Initial assessment: Within 1 week
  • Fix timeline: Depends on severity, but safety-critical issues are highest priority

What Counts as a Security Issue

  • Bypasses of safety systems (crisis, harmful content)
  • Data exposure (conversations, wellness data)
  • Code injection vulnerabilities
  • Denial of service affecting safety features

What Does NOT Count

  • Issues with Ollama itself (report to Ollama)
  • Theoretical attacks requiring physical access
  • Social engineering attacks
  • Issues already documented as limitations

Philosophy

Our security model prioritizes:

  1. User safety first - Crisis detection must never fail silently
  2. Privacy by design - Data stays local by default
  3. Fail safe - When uncertain, err on the side of caution

Thank you for helping keep empathySync safe for everyone.

There aren't any published security advisories