Skip to content

Security: kenwalger/sovereign-memory-demo

Security

SECURITY.md

Security Policy

Supported Versions

Version Supported
0.1.x Yes

Reporting a Vulnerability

If you discover a security vulnerability in Sovereign Memory Demo, please report it responsibly rather than opening a public issue.

Contact: security@sovereignplatform.dev

Include the following in your report:

  • A description of the vulnerability and its potential impact
  • Steps to reproduce the issue
  • Affected component (backend, dataset loader, SDK integration, etc.)
  • Any suggested remediation, if available

We aim to acknowledge reports within 72 hours and will coordinate disclosure timelines with reporters before any public announcement.

Scope

This demo is an educational reference implementation. It intentionally excludes authentication, multi-tenant isolation, and production deployment hardening. Reports related to missing enterprise controls outside the documented MVP scope may be noted but are lower priority.

Safe Harbor

We appreciate good-faith security research conducted within the boundaries described in this policy and will not pursue legal action against researchers who comply with responsible disclosure practices.

There aren't any published security advisories