We provide security updates for the following versions of AgentTune:
| Version | Supported |
|---|---|
| 1.0.x | ✅ |
| < 1.0.0 | ❌ |
Please do not report security vulnerabilities through public GitHub issues.
If you discover a security vulnerability in AgentTune, please report it to us privately by emailing:
When reporting a vulnerability, please include:
- Description of the vulnerability
- Steps to reproduce the issue
- Potential impact of the vulnerability
- Affected versions (if known)
- Suggested fix (if you have one)
- Initial Response: Within 48 hours
- Status Update: Within 7 days
- Fix Timeline: Depends on severity
- Critical: 1-7 days
- High: 7-30 days
- Medium: 30-90 days
- Low: Next planned release
- Acknowledgment: We'll confirm receipt of your report
- Investigation: We'll investigate and assess the severity
- Updates: We'll keep you informed of our progress
- Resolution: We'll notify you when the issue is fixed
- Credit: With your permission, we'll acknowledge your contribution
When using AgentTune, follow these security best practices:
- Keep Updated: Always use the latest version
- Validate Inputs: Sanitize user inputs before passing to models
- Secure Credentials: Never hardcode API keys or tokens
- Review Dependencies: Regularly audit dependencies for vulnerabilities
- Use HTTPS: Always use secure connections for API calls
- Limit Permissions: Run with minimum necessary privileges
- Monitor Logs: Watch for suspicious activity
When contributing to AgentTune:
- Code Review: All code must be reviewed before merging
- Dependency Updates: Keep dependencies up to date
- Input Validation: Always validate and sanitize inputs
- Secrets Management: Never commit secrets or credentials
- Security Testing: Test for common vulnerabilities
- Documentation: Document security-relevant changes
- Only load models from trusted sources
- Verify model checksums when available
- Be cautious with user-provided model paths
- Sanitize dataset inputs to prevent injection attacks
- Validate file paths to prevent directory traversal
- Limit file sizes to prevent resource exhaustion
- Use API rate limiting where applicable
- Implement proper authentication for services
- Validate all external API responses
- Run training in isolated environments when possible
- Monitor resource usage to detect abuse
- Implement proper access controls
AgentTune depends on several third-party libraries. We:
- Regularly update dependencies
- Monitor security advisories
- Use tools like
pip-auditto check for vulnerabilities
To check your installation:
pip install pip-audit
pip-auditWhen a security issue is fixed:
- We will prepare a security advisory
- We will release a patch version
- We will publicly disclose the issue after users have had time to update
- We will credit the reporter (with permission)
Security updates will be:
- Released as patch versions (e.g., 1.0.1)
- Posted as GitHub Security Advisories
- Announced in the CHANGELOG
For security-related questions or concerns:
- Email: security@lexsi.ai
- General Support: support@lexsi.ai
- Website: https://lexsi.ai
We currently do not have a formal bug bounty program, but we:
- Appreciate and acknowledge security researchers
- Provide credit in release notes (with permission)
- May consider rewards on a case-by-case basis for critical vulnerabilities
AgentTune is designed to be used in compliance with:
- Data protection regulations (GDPR, CCPA, etc.)
- Industry security standards
- Research ethics guidelines
Users are responsible for ensuring their use of AgentTune complies with applicable laws and regulations.
Thank you for helping keep AgentTune and its users safe!