Security & responsible disclosure

Report security issues privately.

Please keep vulnerability details out of public issues and comments.

Report a vulnerability

To report a security issue, use GitHub Private Vulnerability Reporting on the Sovereign AI OS repository. Use that route for any component, including ones whose own repository does not yet accept private reports.

Report privately on GitHub ↗

If your finding is specific to Sovereign Vault, you can also report it directly on that repository.

Sovereign Memory Core publishes its own security policy. Read it first if your finding is specific to that component, then report through the route above.

Please do not open a public issue for a suspected vulnerability.

For website or business enquiries unrelated to vulnerability reporting, use the contact page.

What to leave out

Do not send live credentials or personal records. Follow the project’s policy to coordinate any further details privately.

This page does not authorize testing of third-party systems.