Skip to content

Security: itsaddyon/IRIS

Security

SECURITY.md

Security Policy

Reporting Security Issues

Do not open public issues for secrets, credential exposure, biometric data exposure, private database exposure, or access-control weaknesses.

Report security concerns directly to the project owner, Adarsh Arya, through the private contact channel associated with the repository profile.

Sensitive Data Policy

The repository must not contain:

  • API keys;
  • Firebase or Google service-account keys;
  • .env files;
  • SQLite databases;
  • generated reports;
  • generated detection snapshots;
  • biometric encodings, face images, or private driver data;
  • private model artifacts unless intentionally distributed;
  • deployment cache files.

Biometric Module Notice

The face biometric authentication module is archived and disconnected. It should not be re-enabled without a dedicated privacy and security review covering consent, encryption, access control, retention, and deletion.

There aren't any published security advisories