| Version | Supported |
|---|---|
| 1.0.x | ✅ |
Please report security vulnerabilities to security@example.com.
Do not disclose security vulnerabilities publicly until they have been addressed.
ThirdEye includes the following security features:
- No active scanning or exploitation
- No credential validation
- No authentication attempts
- Read-only operations
- Sensitive data masking in output
- No persistent storage of credentials
- Encrypted cache (if configured)
- Configurable data retention
- Rate limiting on API calls
- Timeouts on network operations
- TLS-only external connections
- User-agent identification
- Usage disclaimer on first run
- Clear documentation of limitations
- Exit codes for automation safety
- No hidden or malicious functionality
We follow responsible disclosure practices:
- Report vulnerability privately
- We acknowledge within 48 hours
- We investigate and create fix
- We release patch and credit reporter
- Public disclosure after patch
All dependencies are regularly audited:
cargo auditintegration- Regular dependency updates
- Minimal dependency footprint
- No known vulnerabilities in release
ThirdEye should only be used:
- On systems you own or have permission to test
- In accordance with applicable laws
- For authorized security assessments
- With respect for privacy and ethics