Skip to content

Security: weijt606/owlscope

Security

SECURITY.md

Security Policy

Supported Versions

Owlscope is currently in early-stage open-source release.

Version Supported
0.1.x Yes
< 0.1.0 No

Reporting a Vulnerability

If you discover a security issue, do not open a public issue first.

Please report privately with:

  • Affected component and version
  • Reproduction steps or proof of concept
  • Impact assessment
  • Suggested fix (if available)

Contact:

Response Timeline

  • Initial acknowledgement: within 72 hours
  • Triage and severity assessment: within 7 days
  • Fix and coordinated disclosure: based on severity and impact

Disclosure Guidelines

  • We follow coordinated disclosure.
  • Please avoid sharing exploit details publicly before a fix is available.
  • Credit will be given to reporters who follow responsible disclosure practices.

Security Best Practices for Self-Hosting

  • Use strong secrets and rotate keys regularly.
  • Run behind TLS and a reverse proxy.
  • Restrict network access to PostgreSQL/Redis/Qdrant.
  • Keep dependencies updated.
  • Monitor API and access logs for suspicious activity.

There aren't any published security advisories