Skip to content

Security: fxl112233/HermesBI

Security

SECURITY.md

Security

Do not commit model API keys, Hermes configuration files, raw customer datasets, task databases, evidence artifacts, or generated reports. HermesBI intentionally reads provider credentials from the user's existing Hermes configuration.

The SQL guard and Docker boundary reduce risk but are not a substitute for tenant isolation or a hardened production sandbox. Use synthetic or appropriately authorized data for demonstrations.

To report a vulnerability, open a private GitHub security advisory for this repository rather than a public issue.

There aren't any published security advisories