Skip to content

Security: IA-0/Contextforge

Security

SECURITY.md

Security Policy

Reporting vulnerabilities

If you discover a security issue or accidental exposure of sensitive information, please avoid posting it publicly.

Instead:

  • open a private GitHub security advisory if available;
  • or contact the maintainer directly.

Scope

Current versions of ContextForge do not use:

  • authentication;
  • external AI APIs;
  • databases;
  • remote processing.

The project is currently local-first.

Sensitive information

Never upload:

  • API keys;
  • access tokens;
  • credentials;
  • private datasets;
  • personal information.

Even when testing locally, secrets should remain outside the repository.

There aren't any published security advisories