Skip to content

Security: wimi321/Beacon

Security

SECURITY.md

Security Policy

Scope

Beacon handles emergency workflows, native mobile bridges, and bundled offline guidance. Please report vulnerabilities responsibly.

Reporting

Until a dedicated security inbox is set up, please open a private GitHub security advisory if possible. If that is unavailable, open a minimal issue without sensitive exploit details and note that you need a private follow-up channel.

What to include

  • Affected platform and OS version
  • Device model
  • Reproduction steps
  • Impact summary
  • Whether the issue affects offline inference, native permissions, model packaging, or knowledge delivery

Response goals

  • Acknowledge receipt as quickly as possible
  • Reproduce and assess severity
  • Patch or mitigate before publishing full details

Out of scope

  • General model quality disagreements without a concrete safety or security flaw
  • Third-party upstream issues with no Beacon-specific impact

There aren't any published security advisories