Skip to content

Security: Axiomorix/.github

Security

SECURITY.md

Security Policy

Axiomorix takes the security of its software, services, infrastructure, and users seriously. This policy applies to all repositories and projects maintained by Axiomorix unless a project contains a more specific security policy.

Reporting a Vulnerability

Please do not report security vulnerabilities through public issues, discussions, pull requests, chat channels, or social media.

Use one of the following private reporting methods:

  1. Submit a private vulnerability report through the repository's Security tab, when available.
  2. Email security@axiomorix.com.

Include as much of the following information as possible:

  • The affected repository, package, service, endpoint, version, or commit.
  • A clear description of the vulnerability and its potential impact.
  • Reproduction steps or a minimal proof of concept.
  • Relevant logs, screenshots, requests, responses, or configuration details.
  • Any conditions required to exploit the issue.
  • Suggested mitigations, if known.
  • Whether you intend to disclose the vulnerability publicly.

Do not include sensitive user data, credentials, private keys, access tokens, or unnecessary production data in the report.

If the report contains highly sensitive material, request an encrypted communication channel before sending it.

Response Process

Axiomorix aims to:

  • Acknowledge a report within 3 business days.
  • Complete an initial triage within 10 business days.
  • Provide status updates at least every 14 days while remediation is in progress.
  • Coordinate remediation and disclosure based on severity, exploitability, affected users, and release constraints.

These timeframes are targets rather than guarantees. Complex issues, third-party dependencies, or coordinated releases may require additional time.

Axiomorix may:

  • Request additional technical details.
  • Ask the reporter to verify a proposed fix.
  • Merge duplicate or related reports.
  • Assign a CVE when appropriate and operationally possible.
  • Publish a security advisory, release notes, or remediation guidance.

Supported Versions

Unless a project states otherwise, security fixes are provided for:

  • The latest stable release.
  • The default branch when no stable release exists.
  • Older releases only when explicitly designated as supported.

Pre-release, experimental, archived, abandoned, forked, or end-of-life projects may not receive security updates. Archived repositories should be treated as unsupported unless their documentation says otherwise.

Users are expected to keep Axiomorix software and its dependencies reasonably up to date.

Scope

This policy covers security vulnerabilities in Axiomorix-maintained assets, including where applicable:

  • Source code and released packages.
  • Web applications, APIs, and backend services.
  • Command-line tools, SDKs, agents, and integrations.
  • Authentication, authorization, tenancy, and permission boundaries.
  • Infrastructure-as-code and deployment configuration.
  • Secrets handling, cryptography, and supply-chain controls.
  • Data isolation, data exposure, and unsafe privilege escalation.
  • AI-specific security issues with concrete security impact, such as unauthorized tool execution, cross-tenant data exposure, permission bypasses, or prompt injection that crosses an enforced trust boundary.

A report is generally in scope when it demonstrates a realistic breach of confidentiality, integrity, availability, authentication, authorization, isolation, or another documented security boundary.

Out of Scope

The following are generally not considered security vulnerabilities unless they produce a concrete and reproducible security impact:

  • General product bugs, feature requests, or usability issues.
  • Missing best-practice headers without an exploitable consequence.
  • Automated scanner output without validation.
  • Dependency version reports without a demonstrated affected code path or applicable advisory.
  • Self-XSS or attacks requiring the victim to paste code into a developer console.
  • Denial-of-service claims based only on theoretical resource exhaustion.
  • Rate-limit observations without a meaningful security impact.
  • Clickjacking on pages that do not perform sensitive actions.
  • Username, email, or account enumeration with no material impact.
  • Reports based solely on outdated browser behavior or unsupported platforms.
  • Social engineering, phishing, physical attacks, or attacks against Axiomorix personnel.
  • Vulnerabilities exclusively affecting third-party services not controlled by Axiomorix.
  • Prompt injection or model-output manipulation that does not cross a security, authorization, privacy, or tenancy boundary.
  • Exposure of secrets that are demonstrably invalid, expired, revoked, synthetic, or intended for public use.

Ordinary bugs should be reported through the repository's standard issue tracker.

Research Rules

Security research must be conducted in good faith and in a manner that avoids harm.

You must:

  • Use only accounts, data, and systems you own or are explicitly authorized to test.
  • Minimize access to data and stop testing after establishing a sufficient proof of impact.
  • Avoid persistence, lateral movement, privilege expansion, or modification of unrelated data.
  • Avoid actions that degrade service availability or reliability.
  • Delete any inadvertently accessed data as soon as it is no longer needed for reporting.
  • Keep vulnerability details confidential until coordinated disclosure is complete.

You must not:

  • Perform denial-of-service, load, stress, or resource-exhaustion testing without prior written authorization.
  • Exfiltrate, download, alter, destroy, or retain unnecessary data.
  • Access another person's account or private information beyond the minimum evidence required.
  • Use malware, ransomware, destructive payloads, or persistence mechanisms.
  • Conduct social engineering, phishing, credential stuffing, password spraying, or physical attacks.
  • Test third-party systems, integrations, or infrastructure without authorization from their owners.
  • Publicly disclose an unremediated vulnerability before giving Axiomorix a reasonable opportunity to investigate and respond.

Safe Harbor

Axiomorix will not pursue legal action against researchers who:

  • Act in good faith.
  • Follow this policy.
  • Avoid privacy violations, service disruption, data destruction, and unnecessary access.
  • Report vulnerabilities promptly and privately.
  • Make a reasonable effort to coordinate disclosure.

If your research is uncertain or may exceed this policy, contact Axiomorix before proceeding.

This safe-harbor statement does not authorize activity against third parties, does not waive the rights of affected users or service providers, and does not protect conduct that is unlawful, malicious, extortionate, or outside this policy.

Coordinated Disclosure

Axiomorix supports coordinated vulnerability disclosure.

Unless otherwise agreed, reporters should allow up to 90 days from acknowledgment for investigation, remediation, and disclosure. The timeline may be shortened for actively exploited vulnerabilities or extended when a fix requires substantial ecosystem coordination.

Public disclosure should avoid exposing user data, credentials, operational secrets, or exploit details that would create unnecessary risk.

Axiomorix will make reasonable efforts to credit reporters who request attribution. Reporters may also remain anonymous.

Rewards

Axiomorix does not operate a standing bug bounty program unless a specific project or campaign explicitly states otherwise.

Reports are not eligible for payment, reimbursement, gifts, or other compensation unless agreed in writing before the work is performed.

Security Advisories and Fixes

Security fixes may be delivered through one or more of the following:

  • Patched releases.
  • Repository security advisories.
  • Dependency updates.
  • Configuration changes.
  • Infrastructure or service-side mitigations.
  • Documentation describing required user action.

Where practical, advisories will describe affected versions, severity, impact, mitigations, and upgrade instructions.

Repository Maintainer Responsibilities

Maintainers of Axiomorix projects should:

  • Keep this policy or a project-specific equivalent in the repository root.
  • Enable private vulnerability reporting where supported.
  • Avoid discussing unremediated vulnerabilities in public channels.
  • Restrict report access to people who need it for triage and remediation.
  • Rotate exposed credentials immediately.
  • Preserve relevant evidence without retaining unnecessary personal data.
  • Document supported versions and end-of-life decisions.
  • Publish fixes and advisories in a manner proportionate to the risk.

Policy Precedence

Project-specific security documentation may add requirements or define different support and reporting procedures. Where a project-specific policy conflicts with this document, the project-specific policy takes precedence for that project.

Contact

Security reports: security@axiomorix.com

For non-security bugs, support requests, or feature proposals, use the relevant repository's standard issue tracker or support channel.

There aren't any published security advisories