diff --git a/.github/CODE_OF_CONDUCT.md b/.github/CODE_OF_CONDUCT.md
index 31cd3af9..3cd88395 100644
--- a/.github/CODE_OF_CONDUCT.md
+++ b/.github/CODE_OF_CONDUCT.md
@@ -1,10 +1,131 @@
-# Code of Conduct
+# Contributor Covenant Code of Conduct
-OpenShield is an open, welcoming project.
+## Our Pledge
-- Be respectful in all interactions
-- No harassment, discrimination, or offensive language
-- Constructive feedback only — critique code, not people
-- All contributions welcome regardless of experience level
+We as members, contributors, and leaders pledge to make participation in the
+OpenShield community a harassment-free experience for everyone, regardless of
+age, body size, visible or invisible disability, ethnicity, sex characteristics,
+gender identity and expression, level of experience, education, socio-economic
+status, nationality, personal appearance, race, caste, color, religion, or
+sexual identity and orientation.
-Violations can be reported to the maintainer directly via GitHub.
\ No newline at end of file
+We pledge to act and interact in ways that contribute to an open, welcoming,
+diverse, inclusive, and healthy community.
+
+## Our Standards
+
+Examples of behavior that contributes to a positive environment:
+
+- Demonstrating empathy and kindness toward other people
+- Being respectful of differing opinions, viewpoints, and experiences
+- Giving and gracefully accepting constructive feedback
+- Accepting responsibility and apologizing to those affected by our mistakes,
+ and learning from the experience
+- Focusing on what is best not just for us as individuals, but for the overall
+ community
+
+Examples of unacceptable behavior:
+
+- The use of sexualized language or imagery, and sexual attention or advances of
+ any kind
+- Trolling, insulting or derogatory comments, and personal or political attacks
+- Public or private harassment
+- Publishing others' private information, such as a physical or electronic
+ address, without their explicit permission
+- Other conduct which could reasonably be considered inappropriate in a
+ professional setting
+
+## Enforcement Responsibilities
+
+Community leaders are responsible for clarifying and enforcing our standards of
+acceptable behavior and will take appropriate and fair corrective action in
+response to any behavior that they deem inappropriate, threatening, offensive,
+or harmful.
+
+Community leaders have the right and responsibility to remove, edit, or reject
+comments, commits, code, wiki edits, issues, and other contributions that are
+not aligned to this Code of Conduct, and will communicate reasons for moderation
+decisions when appropriate.
+
+## Scope
+
+This Code of Conduct applies within all community spaces, and also applies when
+an individual is officially representing the community in public spaces.
+Examples of representing our community include using an official email address,
+posting via an official social media account, or acting as an appointed
+representative at an online or offline event.
+
+## Enforcement
+
+Instances of abusive, harassing, or otherwise unacceptable behavior may be
+reported to the project lead **Vishnu Ajith** at vishnu.ajith@owasp.org,
+or contact OWASP directly at . Do not use the
+security advisory channel for conduct reports.
+
+All complaints will be reviewed and investigated promptly and fairly.
+
+All community leaders are obligated to respect the privacy and security of the
+reporter of any incident.
+
+## Enforcement Guidelines
+
+Community leaders will follow these Community Impact Guidelines in determining
+the consequences for any action they deem in violation of this Code of Conduct:
+
+### 1. Correction
+
+**Community Impact:** Use of inappropriate language or other behavior deemed
+unprofessional or unwelcome in the community.
+
+**Consequence:** A private, written warning from community leaders, providing
+clarity around the nature of the violation and an explanation of why the
+behavior was inappropriate. A public apology may be requested.
+
+### 2. Warning
+
+**Community Impact:** A violation through a single incident or series of
+actions.
+
+**Consequence:** A warning with consequences for continued behavior. No
+interaction with the people involved, including unsolicited interaction with
+those enforcing the Code of Conduct, for a specified period of time. This
+includes avoiding interactions in community spaces as well as external channels
+like social media. Violating these terms may lead to a temporary or permanent
+ban.
+
+### 3. Temporary Ban
+
+**Community Impact:** A serious violation of community standards, including
+sustained inappropriate behavior.
+
+**Consequence:** A temporary ban from any sort of interaction or public
+communication with the community for a specified period of time. No public or
+private interaction with the people involved, including unsolicited interaction
+with those enforcing the Code of Conduct, is allowed during this period.
+Violating these terms may lead to a permanent ban.
+
+### 4. Permanent Ban
+
+**Community Impact:** Demonstrating a pattern of violation of community
+standards, including sustained inappropriate behavior, harassment of an
+individual, or aggression toward or disparagement of classes of individuals.
+
+**Consequence:** A permanent ban from any sort of public interaction within the
+community.
+
+## Attribution
+
+This Code of Conduct is adapted from the [Contributor Covenant][homepage],
+version 2.1, available at
+[https://www.contributor-covenant.org/version/2/1/code_of_conduct/][v2.1].
+
+Community Impact Guidelines were inspired by
+[Mozilla's code of conduct enforcement ladder][Mozilla CoC].
+
+For answers to common questions about this code of conduct, see the FAQ at
+. Translations are available at
+.
+
+[homepage]: https://www.contributor-covenant.org
+[v2.1]: https://www.contributor-covenant.org/version/2/1/code_of_conduct/
+[Mozilla CoC]: https://github.com/mozilla/diversity
diff --git a/.github/SECURITY.md b/.github/SECURITY.md
index 315eebd2..f2a96bba 100644
--- a/.github/SECURITY.md
+++ b/.github/SECURITY.md
@@ -2,82 +2,94 @@
## Reporting a Vulnerability
-If you discover a security vulnerability in OpenShield, please **do not open a public GitHub issue**.
-Opening a public issue exposes the vulnerability to bad actors before a fix is available.
+**Do not open a public GitHub issue for security vulnerabilities.**
+Email **vishnu.ajith@owasp.org** with your report. This is the current primary
+channel while GitHub private vulnerability reporting (PVR) is being enabled for
+this organization.
-We will acknowledge your report within 48 hours and work with you to coordinate a fix and responsible disclosure timeline.
+Once PVR is active, you will also be able to report via
+[GitHub's private security advisory feature](https://github.com/OWASP/openshield/security/advisories/new).
-### What to include in your report
-
-To help us triage quickly, please include:
+Please include:
- A description of the vulnerability and its potential impact
-- The affected component (scanner engine, REST API, auth logic, playbooks)
-- Steps to reproduce the issue
-- Any relevant logs, proof-of-concept code, or screenshots
-- The version of OpenShield you were testing (check `git log --oneline -1`)
+- The affected component (scanner engine, REST API, auth logic, playbooks, sentinel)
+- Steps to reproduce or a proof-of-concept (if available)
+- Affected versions or components
+- Any suggested fix (optional)
-The more detail you provide, the faster we can respond.
+### Response timeline
----
+| Stage | Target |
+|---|---|
+| Acknowledgement | Within 48 hours |
+| Initial triage and severity assessment | Within 5 business days |
+| Fix or mitigation | Depends on severity; critical issues within 14 days |
+| Public disclosure | Coordinated with reporter after fix is merged |
-## Supported Versions
-
-| Version | Supported |
-|---------|-----------|
-| 0.3.x | Yes |
-| 0.1.x | No |
-
-Older versions are not patched unless a GitHub Security Advisory explicitly says otherwise. Upgrade to the latest release before filing a report.
+We follow coordinated disclosure. We will credit reporters in
+[SECURITY_ACKNOWLEDGEMENTS.md](https://github.com/OWASP/openshield/blob/main/SECURITY_ACKNOWLEDGEMENTS.md)
+unless they prefer to remain anonymous.
---
-## Disclosure Process
-
-We follow a coordinated disclosure model:
+## Supported Versions
-1. **Report received** -- you email the vulnerability privately
-2. **Acknowledgement** -- we respond within 48 hours to confirm receipt
-3. **Investigation** -- we reproduce and assess the impact
-4. **Fix developed** -- we write and test a patch
-5. **Coordinated release** -- we agree a disclosure date with you (typically 7-14 days after fix)
-6. **Public advisory** -- we publish a GitHub Security Advisory and release the fix
+We actively maintain the latest release on the `main` branch. Security fixes are
+applied to the current release only. We do not backport fixes to older versions.
-We ask that you do not publicly disclose the vulnerability until step 6 is complete.
+| Version | Supported |
+|---|---|
+| Latest (`main`) | Yes |
+| Older releases | No |
---
-## Scope
+## Security Scope
+
+OpenShield is a multi-component security tool. Understanding what each component
+does helps reporters accurately scope their findings.
### In scope
-- Scanner engine (`scanner/`) -- rule logic, Azure SDK calls, output handling
-- REST API (`api/`) -- authentication, authorisation, input validation, JWT handling
-- Compliance framework mappings (`compliance/`) -- data integrity
-- Sentinel integration (`sentinel/`) -- HMAC signing, data upload logic
-- Hardcoded secrets or credentials anywhere in the codebase
+| Component | What it does | Security relevance |
+|---|---|---|
+| `api/` | REST API with JWT/OIDC authentication and role-based access control | Auth bypass, privilege escalation, input validation, JWT handling |
+| `scanner/` | Reads Azure resource configuration via the Azure SDK; does not write | Credential handling, cross-tenant isolation, output integrity |
+| `playbooks/cli/` | Remediation scripts that modify Azure resources when run manually | Command injection, privilege escalation, unsafe Azure mutations |
+| `sentinel/` | Signs and uploads scan data to Azure Log Analytics via HMAC | HMAC signing, credential handling, data integrity |
+| `ai/` | RAG pipeline (embedding, retrieval, chunking) invoked by the API AI endpoints | Prompt injection, data leakage, path traversal on document loading |
+| `compliance/` | Compliance framework mappings consumed by the API and scanner | Logic errors that incorrectly map controls, suppressing true positives |
+| `frontend/` | React dashboard that displays scan results and compliance reports | XSS, CSRF, insecure API consumption, auth state handling |
+| `website/` | Astro project website and documentation | XSS, content injection, dependency vulnerabilities |
+| Hardcoded secrets | Anywhere in the codebase | Any real credential committed to the repo |
### Out of scope
-- Vulnerabilities in third-party dependencies -- report those to the upstream maintainer
+- Vulnerabilities in third-party dependencies — report those to the upstream maintainer
- Security issues in infrastructure you deploy OpenShield to (your Azure environment, your PostgreSQL instance)
+- False-positive scan findings due to unsupported Azure API versions or preview features
+- Rate limiting or throttling by the Azure ARM API
- Social engineering attacks
- Physical security
----
-
-## Recognition
-
-We value responsible disclosure. Researchers who report valid vulnerabilities will be:
-
-- Acknowledged by name (or pseudonym if preferred) in the release notes for the fix
-- Listed in [`SECURITY_ACKNOWLEDGEMENTS.md`](../SECURITY_ACKNOWLEDGEMENTS.md)
+### Clarification on read-only behavior
-We do not currently offer a bug bounty programme, but we are grateful for every report.
+The `scanner/` component is read-only: it reads Azure configuration and does not
+modify resources. The `playbooks/cli/` scripts are separate executables that a
+human operator runs manually; they do modify Azure resources. The REST API and
+sentinel components are active network services.
---
-## Contact
+## Security Controls in This Repository
-**Email: vishnu.ajith@owasp.org**
+| Control | Implementation |
+|---|---|
+| Static analysis (SAST) | Semgrep, Bandit in CI + CodeQL (separate workflow) on every PR |
+| Dependency scanning | Dependabot alerts (GitHub) + pip-audit in CI |
+| Secret scanning | Gitleaks in CI |
+| Container scanning | Trivy in CI |
+| SBOM generation | Syft in CI |
+| DCO sign-off | DCO check runs on every pull request |