Skip to content

Security: meshguard/community

Security

SECURITY.md

Security Policy

MeshGuard takes security seriously. We appreciate your help in keeping MeshGuard and our users safe.

Reporting a Vulnerability

Please do not report security vulnerabilities through public GitHub issues.

Instead, report security vulnerabilities via email to:

📧 security@meshguard.app

What to Include

Please include as much of the following information as possible:

  • Type of vulnerability (e.g., authentication bypass, injection, data exposure)
  • Affected component (Gateway, SDK, Dashboard, etc.)
  • Steps to reproduce the vulnerability
  • Proof of concept code or screenshots, if available
  • Potential impact of the vulnerability
  • Suggested remediation if you have one

What to Expect

  1. Acknowledgment — We will acknowledge receipt within 48 hours
  2. Assessment — Our security team will assess the vulnerability
  3. Updates — We will keep you informed of our progress
  4. Resolution — We aim to resolve critical issues within 7 days
  5. Credit — With your permission, we will credit you in our security acknowledgments

Scope

In Scope

  • MeshGuard Gateway
  • MeshGuard SDKs (Node.js, Python, Go)
  • dashboard.meshguard.app
  • api.meshguard.app
  • Authentication and authorization systems
  • Data handling and encryption

Out of Scope

  • Third-party services and integrations
  • Social engineering attacks
  • Physical attacks
  • Issues in services we don't control
  • Denial of service attacks

Safe Harbor

We support responsible disclosure. If you:

  • Act in good faith
  • Avoid privacy violations and data destruction
  • Do not exploit vulnerabilities beyond what is necessary to demonstrate them
  • Report vulnerabilities promptly

We commit to:

  • Not pursue legal action against you
  • Work with you to understand and resolve the issue
  • Acknowledge your contribution (with your permission)

Security Best Practices

When using MeshGuard, we recommend:

  1. Rotate API keys regularly and after any suspected compromise
  2. Use environment variables for credentials — never commit them to code
  3. Enable audit logging to monitor agent activity
  4. Implement least-privilege policies for agent permissions
  5. Monitor the status page at status.meshguard.app

Contact


Thank you for helping keep MeshGuard secure.

There aren’t any published security advisories