docs: add privacy and security policies

This commit is contained in:
Kieran Klaassen
2026-03-06 14:55:20 -08:00
parent ca57c67c1c
commit 69f2a96e66
2 changed files with 67 additions and 0 deletions

29
SECURITY.md Normal file
View File

@@ -0,0 +1,29 @@
# Security Policy
## Supported Versions
Security fixes are applied to the latest version on `main`.
## Reporting a Vulnerability
Please do not open a public issue for undisclosed vulnerabilities.
Instead, report privately by emailing:
- `kieran@every.to`
Include:
- A clear description of the issue
- Reproduction steps or proof of concept
- Impact assessment (what an attacker can do)
- Any suggested mitigation
We will acknowledge receipt as soon as possible and work with you on validation, remediation, and coordinated disclosure timing.
## Scope Notes
This repository primarily contains plugin instructions/configuration plus a conversion/install CLI.
- Plugin instruction content itself does not run as a server process.
- Security/privacy behavior also depends on the host AI tool and any external integrations you explicitly invoke.
For data-handling details, see [PRIVACY.md](PRIVACY.md).