Skip to content

Security: NodeOps-app/rakazo

Security

SECURITY.md

Security

Reporting vulnerabilities

Email security@rakazo.com only. Do not open public GitHub issues for security bugs.

Please include:

  • Steps to reproduce
  • Impact (what an attacker could do)
  • Whether the issue is already public

We will acknowledge your report and work on a fix. Please do not file a public issue for unfixed vulnerabilities.

Other contact

Scope

This policy covers the Rakazo self-hosted product in this repository.

Out of scope:

  • Third-party AI models and their APIs
  • Composio, E2B, and other external services
  • Operator misconfiguration (exposed secrets, open databases, weak passwords)

Supported versions

We support security fixes on the current main branch and the latest release (beta).

There is no bug bounty program at this time.

There aren't any published security advisories