Skip to content

Security: kontourai/surface

Security

SECURITY.md

Security Policy

Reporting A Vulnerability

Do not open a public GitHub issue for security reports.

Send a private report to security@kontourai.com with:

  • a short summary of the issue
  • affected versions or commit range
  • reproduction steps or proof of concept
  • impact assessment
  • any suggested remediation

If email is not possible, open a private GitHub security advisory draft instead.

What To Expect

  • We will acknowledge receipt within 3 business days.
  • We will aim to confirm impact and next steps within 7 business days.
  • We will coordinate on disclosure timing once a fix exists or a mitigation is available.

Scope

Security issues in scope include:

  • command execution or injection flaws
  • privilege or permission escalation
  • unsafe handling of secrets or credentials
  • artifact or workflow trust-boundary violations
  • supply-chain or package-publishing exposure in this repository

Quality bugs, documentation bugs, and feature requests should go through the normal issue tracker.

There aren't any published security advisories