Skip to content

Security: CSOAI-ORG/explainability-report-mcp

Security

SECURITY.md

Security Policy

Supported Versions

Version Supported
Latest Yes
< Latest No

Reporting a Vulnerability

If you discover a security vulnerability, please report it responsibly:

  1. Email: security@csoai.org
  2. Do NOT open a public GitHub issue for security vulnerabilities
  3. Include a description of the vulnerability and steps to reproduce

We will acknowledge receipt within 48 hours and provide a detailed response within 5 business days.

Security Measures

  • All attestations are HMAC-SHA256 signed
  • API keys are validated server-side
  • Rate limiting is enforced per tier
  • No sensitive data is logged or stored

Disclosure Policy

We follow coordinated disclosure. We will work with you to understand and address the issue before any public disclosure.

There aren't any published security advisories