Files
ai-disclosure-standard/SECURITY.md
T
jbergner 4e2c648ede
release-tag / release-image (push) Has been cancelled
2.0.0 Production-RC
2026-07-24 07:23:59 +02:00

1.1 KiB

Security

Supported version

Security fixes are intended for the current 2.x line.

Runtime hardening

The supplied container/deployment examples run non-root with a read-only root filesystem, dropped Linux capabilities and no privilege escalation. Kubernetes examples use RuntimeDefault seccomp and disable automatic service-account token mounting.

Runtime secrets can be read from files through LICENSE_TOKEN_FILE and BULK_API_KEY_FILE. Do not commit real licence tokens or API keys.

The dedicated bulk image is fail-closed by default: it requires a valid runtime licence, the bulk_api capability and an API key configuration before becoming ready.

Reporting

Do not open public issues containing active licence tokens, API keys, private infrastructure details or exploitable security findings. Use the project contact channel configured by the maintainer.

Trust store

Only public issuer/lease keys from the operator's Universal License Platform belong in internal/app/trusted_keys.json. Never place private signing keys in this repository or image.