This document describes the governance model for the open-source CONTEXA core repository.
This repository governs the public open-source core:
- runtime control engine
- Spring integration and starter surfaces
- open-source documentation and public trust surfaces
- issue intake, contribution review, and release stewardship
Enterprise operational surfaces are managed separately.
CONTEXA currently operates under a maintainer-led governance model.
At the current public OSS stage, core maintainers are responsible for:
- architecture direction
- release scope decisions
- issue triage and prioritization
- contribution review and merge decisions
- public security and disclosure coordination
- documentation quality and public positioning
Changes are evaluated against the following priorities:
- runtime security correctness
- post-authentication control integrity
- public API and starter stability
- documentation clarity and operational trustworthiness
- maintainability and release readiness
The public OSS core is versioned and released with semantic versioning in principle.
Each public release should provide:
- versioned change history
- release notes
- current public trust links
- security reporting path
- clear distinction between OSS core and separate enterprise surfaces
Security issues should follow the reporting path defined in SECURITY.md and the public security.txt surface.
- Main site: https://ctxa.ai
- Demo / verification console: https://demo.ctxa.ai
- Documentation site: https://docs.ctxa.ai
- Public benchmark: https://ctxa.ai/benchmark
- Security policy: SECURITY.md
- Public security.txt: https://ctxa.ai/.well-known/security.txt