| Version | Supported |
|---|---|
| 1.0.x | ✅ |
| < 1.0 | ❌ |
The GhostNet AI team takes security and user privacy seriously. If you discover a security vulnerability in GhostNet AI, please report it responsibly.
- Do NOT report security vulnerabilities via public GitHub issues.
- Email the core security maintainers directly at
security@ghostnet.aior submit a private vulnerability report via GitHub Security Advisories. - Include detailed steps to reproduce the vulnerability, including sample payloads and affected endpoints or components.
- We will acknowledge receipt of your vulnerability report within 48 hours.
- We will provide a status update and remediation timeline within 5 business days.
- Once verified and patched, we will publish a security advisory crediting you for the responsible disclosure.
For full architectural security details, threat vectors, and data isolation policies, refer to docs/SECURITY.md and docs/THREAT_MODEL.md.