Skip to content

Security: kylie-grace/ai-audio-studio

SECURITY.md

Security Policy

Reporting Vulnerabilities

  • Use GitHub private vulnerability reporting for security disclosures.
  • Expect acknowledgement within 72 hours.

Scope

In scope:

  • auth bypass
  • approval gate bypass
  • credential leakage

Out of scope:

  • issues that require physical access to an operator machine without any platform vulnerability
  • problems caused only by placeholder credentials in env.example

Disclosure Policy

  • Report privately first.
  • Do not publish exploit details until the issue is acknowledged and a fix window is agreed.
  • Include reproduction steps, affected files or endpoints, and deployment assumptions.

AGPL Warranty Note

This project is distributed under AGPL-3.0-or-later without warranty. That license posture does not reduce the importance of promptly reporting and fixing real security issues.

There aren't any published security advisories