morphit/SECURITY.md
Morphit Team c5d07e2700
Some checks failed
morphit-release / Build + publish release tarball (push) Has been cancelled
Regenerate llms-full.txt for the Featured-slot FAQ 5->3 fix
No version change (still 1.0.0, still un-tagged).
2026-07-06 18:49:42 -07:00

1 KiB

Security policy

For Morphit's full security posture, threat model, and responsible-disclosure process, please see docs/SECURITY.md.

Reporting a vulnerability

Two channels, in order of preference:

  1. Matrix DM to @agorise:matrix.org — fastest path to a real human on the project. End-to-end encrypted by default in Element / most Matrix clients. Use this for anything sensitive enough that a passive observer shouldn't see it.
  2. Confidential issue at git.agorise.net/agorise/morphit — Forgejo supports the Confidential flag on issues.

We commit to:

  • Acknowledging receipt within 72 hours
  • Triaging severity within 7 days
  • Coordinating a fix-and-disclose timeline with you
  • Crediting your finding in the project changelog (with your consent)

For full disclosure-program details (severity ladder, scope, what's out-of-scope, the discretionary recognition program), read docs/SECURITY.md.