Files
ai-disclosure-standard/SECURITY.md
T
2026-07-20 21:03:05 +02:00

942 B

Security policy

Version 1.6.x is the supported line in this project archive.

License integration

  • Customer installations configure only LICENSE_TOKEN and optional client settings.
  • LICENSE_PUBLIC_KEY, private keys and signing keys are not supported.
  • Public issuer and lease keys are embedded from internal/app/trusted_keys.json at build time.
  • Key generation, license issuance, token registries, revocation and lease signing exist only in the standalone Universal License Platform.
  • Use HTTPS for hybrid and online verification.
  • Protect the hybrid cache directory from other local users; it contains only signed lease tokens, not private keys.

Online mode fails closed if the platform is unavailable. Hybrid mode may continue only while a previously signed lease remains valid within the grace period encoded in the license.

Report suspected vulnerabilities privately to the project operator before public disclosure.