Skip to content

Security: INNOVATION-SYNERGY-AI/.github

Security

SECURITY.md

Security Policy

This is the organization-wide security policy for INNOVATION SYNERGY AI. A repository that ships its own SECURITY.md overrides this file.

Reporting a vulnerability

Do not open a public issue for a security vulnerability.

Email michael@innovationsynergyai.com with:

  • A description of the issue and the impact you believe it has
  • The repository, app, or endpoint affected, and the version or build if you know it
  • Steps to reproduce, including any proof-of-concept code
  • Whether the issue is already public anywhere

You will get an acknowledgement within two business days. We will confirm whether the report is in scope, agree on a fix timeline with you, and let you know when a fix has shipped.

Scope

In scope: our published iOS, iPadOS, and macOS applications, the backend services and integrations that support them, and code in public repositories under this organization.

Out of scope: reports generated solely by automated scanners with no demonstrated impact, denial of service through sheer volume of traffic, social engineering of our staff or clients, and issues in third-party platforms such as Apple's services, which should be reported to that vendor.

Client applications

Several of our apps are built and operated for clients. If your report concerns a client-branded app, send it to us rather than to the client, and we will coordinate disclosure with them.

Disclosure

Please give us a reasonable window to ship a fix before disclosing publicly. App Store review adds time we do not control, so we will tell you what the realistic release date looks like. We are happy to credit you in release notes if you would like.

What we ask

Test only against your own accounts and data. Do not access, modify, or retain anyone else's information, and do not degrade service for real users while testing.

There aren't any published security advisories