Skip to content

Security: claroshq/claros

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

If you discover a security vulnerability in Claros, please report it privately.

Email: security@claros.org

Please include:

  • Description of the vulnerability
  • Steps to reproduce
  • Potential impact
  • Suggested fix (if you have one)

Response Expectations

Claros is maintained by a solo developer. Honest expectations:

  • Acknowledgment within 48 hours (usually faster)
  • Assessment and fix timeline within 1 week
  • Critical issues (data exposure, RCE) are prioritized above all other work

Scope

This policy covers the Claros engine code in this repository. For issues with the hosted Cloud service at app.claros.org, use the same email.

No Bounty Program

There is no bug bounty program at this time. Credit is given in release notes for responsibly disclosed vulnerabilities (unless you prefer to remain anonymous).

Supported Versions

Only the latest release is supported with security patches. Running older versions is at your own risk - update regularly.

There aren't any published security advisories