Skip to content

Security: rumi7911/gridtwin

SECURITY.md

Security Policy

Supported version

GridTwin is an experimental hackathon proof of concept. Security fixes are applied to the latest commit on main and the public deployment at gridtwin.vercel.app.

Reporting a vulnerability

Please do not disclose security vulnerabilities in a public issue. Use GitHub's private Report a vulnerability flow and include:

  • the affected URL, component, or WebMCP tool;
  • steps to reproduce;
  • the expected and observed behavior; and
  • any suggested mitigation.

GridTwin is client-only and intentionally has no accounts, API keys, backend, or long-term data store. Reports concerning WebMCP trust boundaries, tool input validation, browser state recovery, or unintended authority escalation are especially valuable.

Scope reminder

The energy model uses synthetic data and produces indicative planning estimates. It is not engineering, investment, safety, or operational advice.

There aren't any published security advisories