Skip to content

Security: iberi22/xavier

Security

SECURITY.md

Security Policy

Supported Versions

We currently support the latest stable release with security updates. Older versions may receive patches on a case-by-case basis.

Version Supported
latest ✅ Supported
< latest ⚠️ Limited support

Reporting a Vulnerability

We take the security of Xavier seriously. If you discover a security vulnerability, please report it privately.

Do not report security vulnerabilities through public GitHub issues.

How to Report

  1. Email: Send details to security@swal.ai
  2. PGP Key: (TBD — encrypted reports coming soon)
  3. Response Timeline: We aim to acknowledge receipt within 48 hours and provide an initial assessment within 5 business days.

What to Include

  • A clear description of the vulnerability
  • Steps to reproduce (proof of concept preferred)
  • Affected versions
  • Any potential impact or exploit scenarios
  • Your contact information for follow-up

Disclosure Policy

We follow a coordinated disclosure process:

  1. We investigate and confirm the issue
  2. We develop and test a fix
  3. We release a security advisory and update
  4. We grant you credit for the discovery (unless you prefer anonymity)

We aim to release fixes within 14 days of confirmation, depending on severity.

Scope

This policy covers:

  • The Xavier context engine (Rust binary)
  • REST API endpoints
  • Authentication and authorization mechanisms
  • Data storage and encryption

Recognition

We maintain a Security Hall of Fame for researchers who responsibly disclose vulnerabilities. If you'd like to be credited, let us know when you report.


Last updated: 2026-05-06

There aren't any published security advisories