Skip to content

Security: telophasehq/hiro-agent

SECURITY.md

Security Policy

Reporting a Vulnerability

If you discover a security vulnerability, do not disclose it publicly first.

Please report via:

Include:

  • affected component/path
  • reproduction steps
  • impact assessment
  • suggested fix (if available)

Response Expectations

  • Initial acknowledgment: within 3 business days
  • Triage and severity assessment: as soon as possible
  • Coordinated disclosure after fix validation

Scope

This policy applies to the code in this repository and released package artifacts.

There aren't any published security advisories